Page 20 of 488 results (0.008 seconds)

CVSS: 9.8EPSS: 12%CPEs: 14EXPL: 0

21 Sep 2021 — ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. ManageEngine ADSelfService Plus versiones anteriores a 6112, es vulnerable a una toma de control de cuentas de usuario de dominio • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release •

CVSS: 9.8EPSS: 4%CPEs: 14EXPL: 0

10 Sep 2021 — Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, es vulnerable a una inyección SQL mientras se vinculan las bases de datos • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 9.8EPSS: 2%CPEs: 14EXPL: 0

10 Sep 2021 — Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. Zoho ManageEngine ADSelfService Plus versiones 6111 y anteriores, son vulnerables a una toma de posesión de aplicaciones vinculadas • https://pitstop.manageengine.com/portal/en/community/topic/adselfservice-plus-6112-hotfix-release •

CVSS: 7.5EPSS: 2%CPEs: 1EXPL: 0

10 Sep 2021 — Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. Zoho ManageEngine DesktopCentral antes de la versión 10.0.709 permite a cualquiera obtener la APIKEY de un usuario válido sin necesidad de autenticación • https://www.manageengine.com/products/desktop-central/help/introduction/release_notes.html • CWE-287: Improper Authentication •

CVSS: 9.8EPSS: 94%CPEs: 170EXPL: 7

07 Sep 2021 — Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. Zoho ManageEngine ADSelfService Plus versiones 6113 y anteriores, es vulnerable a una omisión de autenticación de la API REST con una ejecución de código remota resultante Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. • https://packetstorm.news/files/id/165085 • CWE-706: Use of Incorrectly-Resolved Name or Reference •

CVSS: 9.8EPSS: 89%CPEs: 65EXPL: 0

01 Sep 2021 — Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. Zoho ManageEngine ServiceDesk Plus versiones anteriores a 11302, es vulnerable a una omisión de autenticación que permite algunas URLs REST-API sin autenticación Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication • https://www.manageengine.com • CWE-306: Missing Authentication for Critical Function •

CVSS: 6.4EPSS: 2%CPEs: 1EXPL: 1

01 Sep 2021 — A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4. Un ataque de tipo Cross-Site Scripting (XSS) puede causar una ejecución de código arbitrario (J... • https://cybersecurityworks.com/zerodays/cve-2020-29322-telnet-hardcoded-credentials.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 8%CPEs: 6EXPL: 0

30 Aug 2021 — Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, son vulnerables a una evasión de la restricción de acceso al portal de administración. • https://blog.stmcyber.com/vulns/cve-2021-37421 • CWE-345: Insufficient Verification of Data Authenticity •

CVSS: 9.8EPSS: 18%CPEs: 6EXPL: 0

30 Aug 2021 — Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, permiten omitir el CAPTCHA debido a una comprobación inapropiada de los parámetros. • https://blog.stmcyber.com/vulns/cve-2021-37417 • CWE-287: Improper Authentication •

CVSS: 6.1EPSS: 7%CPEs: 6EXPL: 0

30 Aug 2021 — Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. Zoho ManageEngine ADSelfService Plus versiones 6103 y anteriores, es vulnerable a un ataque de tipo XSS reflejado en la página loadframe. • https://blog.stmcyber.com/vulns/cve-2021-37416 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •