Vulnerabilities > Zohocorp > Manageengine Servicedesk Plus > 12.0

DATE CVE VULNERABILITY TITLE RISK
2022-07-12 CVE-2022-35403 Unspecified vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email.
network
low complexity
zohocorp
5.0
2022-04-05 CVE-2022-25245 Missing Authentication for Critical Function vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
network
low complexity
zohocorp CWE-306
5.3
2021-12-23 CVE-2021-44526 Unspecified vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
network
zohocorp
6.8
2019-08-21 CVE-2019-15045 Information Exposure vulnerability in Zohocorp Manageengine Servicedesk Plus
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration.
network
low complexity
zohocorp CWE-200
5.3
2019-08-14 CVE-2019-15046 Improper Authentication vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
network
low complexity
zohocorp CWE-287
5.0