Vulnerabilities > Zohocorp > Manageengine Admanager Plus > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-10-07 CVE-2021-37921 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37920 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37919 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37918 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37762 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-09-27 CVE-2021-37761 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-09-27 CVE-2021-37539 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-09-22 CVE-2021-37927 Improper Verification of Cryptographic Signature vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
network
low complexity
zohocorp CWE-347
critical
9.8
2021-09-22 CVE-2021-37925 OS Command Injection vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
network
low complexity
zohocorp CWE-78
critical
9.8
2021-09-21 CVE-2021-37424 Unspecified vulnerability in Zohocorp Manageengine Admanager Plus 6.1
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
network
low complexity
zohocorp
critical
9.8