Known vulnerabilities in Zoho ManageEngine Desktop Central

Software CPE: cpe:2.3:a:zohocorp:zoho_manageengine_desktop_central:*:*:*:*:*:*:*:*
Total vulnerabilities: 33
Public exploits: 8
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Zoho ManageEngine Desktop Central Zoho ManageEngine Desktop Central is affected by 33 known vulnerabilities: 13 high, 10 medium, 10 low Critical High Medium Low

Vulnerabilities (33)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU70548 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-47523
CWE-89 Medium
No
No
10.1.2228.19 01.01.2023 SB2023010102
SB2023010703
SB2023011720
and 1 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Available
Exploited
10.1.2228.10 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU67040 - Exposure of sensitive information to an unauthorized actor
CVE-2022-23779
CWE-200 Low
Available
No
10.1.2137.8 06.09.2022 SB2022090662
#VU60109 - Permissions, Privileges, and Access Controls
CVE-2022-23863
CWE-264 Medium
No
No
10.1.2137.10 28.01.2022 SB2022012801
#VU59675 - Improper Authentication
CVE-2021-44757
CWE-287 High
No
No
10.1.2137.9 18.01.2022 SB2022011804
#VU58523 - Improper Authentication
CVE-2021-44515
CWE-287 High
No
Exploited
10.1.2127.18, 10.1.2137.3 06.12.2021 SB2021120606
#VU51488 - Integer overflow
CWE-190 High
No
No
10.0.600 15.03.2021 SB2020102052
#VU51487 - Unrestricted Upload of File with Dangerous Type
CWE-434 Medium
No
No
10.0.681 15.03.2021 SB2021031516
#VU48148 - Permissions, Privileges, and Access Controls
CWE-264 High
No
No
10.0.604 04.11.2020 SB2020110413
#VU48147 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
10.0.604 04.11.2020 SB2020110413
#VU46831 - Integer overflow
CWE-190 Medium
No
No
10.0.581 21.09.2020 SB2020092105
#VU46735 - Integer overflow
CVE-2020-24397
CWE-190 High
Available
No
10.0.575 15.09.2020 SB2020091515
#VU46734 - Improper Authentication
CWE-287 High
No
No
10.0.575 15.09.2020 SB2020091515
#VU46733 - Permissions, Privileges, and Access Controls
CWE-264 High
No
No
10.0.571 15.09.2020 SB2020091514
#VU31935 - Permissions, Privileges, and Access Controls
CWE-264 High
No
No
10.0.550 27.07.2020 SB2020072747
#VU31934 - Exposure of sensitive information to an unauthorized actor
CWE-200 Medium
No
No
10.0.554 27.07.2020 SB2020072746
#VU31933 - Improper Authentication
CVE-2020-15589
CWE-287 High
Available
No
10.0.556 27.07.2020 SB2020072745
#VU31932 - Integer overflow
CVE-2020-15588
CWE-190 High
Available
No
10.0.556 27.07.2020 SB2020072745
#VU28255 - Uncontrolled Search Path Element
CWE-427 Medium
No
No
10.0.516 26.05.2020 SB2020052613
#VU28253 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79 Low
No
No
10.0.527 26.05.2020 SB2020052613


Showing elements 1 - 20 out of 33