Opmanager
This hub aggregates every CVE we track for Opmanager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
1
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Opmanager.
- CVE-2025-9227Stored XSS6.5
- CVE-2025-41437Reflected XSS4.3
- CVE-2024-6748SQL Injection8.3
- CVE-2024-36038Stored XSS6.3
- CVE-2023-47211A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can s...9.1
- CVE-2022-43473A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve ...5.8
- CVE-2022-37024Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) a...8.8
- CVE-2020-19554Cross Site Scripting (XSS) vulnerability exists in ManageEngine OPManager <=12.5.174 when the API key contains an XML-based XSS payload.6.1
- CVE-2007-5891Multiple cross-site scripting (XSS) vulnerabilities in jsp/Login.do in ManageEngine OpManager MSP Edition and OpManager 7.0 allow remote attackers to inject arbitrary web script or HTML via the (1)...4.3
Product normalization is registry-driven with AI assist and human review. How it works