Vulnerabilities > Zohocorp > Manageengine Servicedesk Plus > 14.0

DATE CVE VULNERABILITY TITLE RISK
2022-11-23 CVE-2022-40771 XXE vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.
network
low complexity
zohocorp CWE-611
4.9
2022-11-23 CVE-2022-40772 Unspecified vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
network
low complexity
zohocorp
6.5
2019-08-21 CVE-2019-15045 Information Exposure vulnerability in Zohocorp Manageengine Servicedesk Plus
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration.
network
low complexity
zohocorp CWE-200
5.3