CVE-2026-14828
- EPSS 1.44%
- Veröffentlicht 02.09.2026 07:25:47
- Zuletzt bearbeitet 08.09.2026 18:35:10
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
CVE-2026-12263
- EPSS 0.7%
- Veröffentlicht 13.08.2026 10:18:35
- Zuletzt bearbeitet 31.08.2026 19:22:43
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
CVE-2026-11840
- EPSS 1.58%
- Veröffentlicht 13.08.2026 07:35:28
- Zuletzt bearbeitet 31.08.2026 19:22:43
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
CVE-2026-5785
- EPSS 1.39%
- Veröffentlicht 16.04.2026 13:46:28
- Zuletzt bearbeitet 17.04.2026 15:17:00
Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module.
CVE-2025-11669
- EPSS 0.74%
- Veröffentlicht 13.01.2026 14:16:37
- Zuletzt bearbeitet 02.02.2026 15:42:06
Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.
CVE-2024-5546
- EPSS 3.04%
- Veröffentlicht 28.08.2024 09:15:11
- Zuletzt bearbeitet 19.09.2024 14:39:09
Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option.
CVE-2024-27313
- EPSS 1.29%
- Veröffentlicht 29.05.2024 11:16:02
- Zuletzt bearbeitet 27.11.2024 16:24:25
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.
CVE-2024-27312
- EPSS 0.9%
- Veröffentlicht 20.05.2024 13:15:23
- Zuletzt bearbeitet 25.11.2024 15:14:53
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to th...
CVE-2023-6105
- EPSS 0.69%
- Veröffentlicht 15.11.2023 21:15:08
- Zuletzt bearbeitet 13.02.2025 18:16:03
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use t...
CVE-2023-2291
- EPSS 0.81%
- Veröffentlicht 26.04.2023 21:15:09
- Zuletzt bearbeitet 03.02.2025 18:15:30
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that w...