📦 Manageengine Applications Manager

by Zohocorp

🔍 What is Manageengine Applications Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-15533

CRITICAL CVSS 9.8 Oct 1, 2020

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on Zoho ManageEngine Application Manager installations. It affects systems running vulnerable versions, potentiall...

CVE-2020-15394

CRITICAL CVSS 9.8 Sep 25, 2020

This vulnerability allows unauthenticated attackers to execute SQL injection attacks via the REST API in Zoho ManageEngine Applications Manager, which can lead to remote code execution. It affects all...

CVE-2024-41140

HIGH CVSS 8.1 Jan 29, 2025

This vulnerability allows attackers with existing user accounts to escalate privileges by exploiting incorrect authorization checks in the update user function. It affects ManageEngine Applications Ma...

CVE-2020-35765

HIGH CVSS 8.8 Feb 5, 2021

This vulnerability allows authenticated attackers to execute SQL injection attacks via the resourceid parameter in Zoho ManageEngine Applications Manager. Attackers can potentially read, modify, or de...

CVE-2025-9787

MEDIUM CVSS 6.1 Dec 18, 2025

ManageEngine Applications Manager versions 177400 and below contain a stored cross-site scripting vulnerability in the NOC view. This allows attackers to inject malicious scripts that execute when use...

CVE-2025-6239

MEDIUM CVSS 6.5 Oct 21, 2025

ManageEngine Applications Manager versions 176800 and below contain an information disclosure vulnerability in the File/Directory monitor component. This allows attackers to access sensitive informati...

CVE-2025-27930

MEDIUM CVSS 6.4 Jul 23, 2025

ManageEngine Applications Manager versions 176600 and prior contain a stored cross-site scripting (XSS) vulnerability in the File/Directory monitor feature. This allows attackers to inject malicious s...

CVE-2024-5678

MEDIUM CVSS 4.7 Aug 1, 2024

This vulnerability allows authenticated administrators in Zohocorp ManageEngine Applications Manager to execute arbitrary SQL commands through the Create Monitor feature. Attackers with admin credenti...