CVE-2025-11248
- EPSS 0.16%
- Veröffentlicht 27.10.2025 13:15:42
- Zuletzt bearbeitet 28.10.2025 13:22:12
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.
CVE-2025-7473
- EPSS 0.03%
- Veröffentlicht 21.10.2025 10:58:47
- Zuletzt bearbeitet 23.10.2025 14:36:06
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
CVE-2025-5496
- EPSS 0.01%
- Veröffentlicht 21.10.2025 10:15:34
- Zuletzt bearbeitet 28.10.2025 15:36:52
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
CVE-2025-5494
- EPSS 0.01%
- Veröffentlicht 25.09.2025 14:15:46
- Zuletzt bearbeitet 22.10.2025 19:42:49
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
CVE-2024-9097
- EPSS 0.08%
- Veröffentlicht 05.02.2025 13:15:23
- Zuletzt bearbeitet 22.10.2025 20:27:48
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
CVE-2024-10203
- EPSS 0.05%
- Veröffentlicht 07.11.2024 10:15:05
- Zuletzt bearbeitet 21.11.2025 19:13:24
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
CVE-2024-38868
- EPSS 0.12%
- Veröffentlicht 30.08.2024 18:15:06
- Zuletzt bearbeitet 04.09.2024 19:13:29
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
CVE-2023-6105
- EPSS 0.08%
- Veröffentlicht 15.11.2023 21:15:08
- Zuletzt bearbeitet 13.02.2025 18:16:03
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use t...