Vulnerabilities > Zohocorp > Manageengine Supportcenter Plus > 11.0

DATE CVE VULNERABILITY TITLE RISK
2021-11-30 CVE-2021-43295 Cross-site Scripting vulnerability in Zohocorp Manageengine Supportcenter Plus 11.0
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
network
low complexity
zohocorp CWE-79
6.1
2021-11-30 CVE-2021-43296 Server-Side Request Forgery (SSRF) vulnerability in Zohocorp Manageengine Supportcenter Plus 11.0
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
network
low complexity
zohocorp CWE-918
7.5
2021-11-29 CVE-2021-44077 Missing Authentication for Critical Function vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution.
network
low complexity
zohocorp CWE-306
critical
9.8