CVE-2025-8309
- EPSS 0.04%
- Published 20.08.2025 16:53:29
- Last modified 22.08.2025 18:09:17
There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus products by Zohocorp. This vulnerability impacts Asset Explorer versions before 7710...
CVE-2025-3444
- EPSS 0.08%
- Published 22.05.2025 10:31:48
- Last modified 17.06.2025 20:18:53
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
CVE-2024-27314
- EPSS 2.6%
- Published 27.05.2024 07:15:09
- Last modified 17.06.2025 20:18:05
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by t...
CVE-2008-1432
- EPSS 0.26%
- Published 20.03.2008 18:44:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine SupportCenter Plus 7.0.0 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, a related issue to CVE-2008-1299. NOTE: the provenanc...