Manageengine key manager plus
This hub aggregates every CVE we track for Manageengine key manager plus, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
1
Critical
1
High
1
In CISA KEV
Severity distribution
MEDIUM3HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 5 most recently published vulnerabilities affecting Manageengine key manager plus.
- CVE-2022-47966Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because ...KEV9.8
- CVE-2022-24447An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associa...6.5
- CVE-2022-24446An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to t...4.3
- CVE-2021-28382Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.5.4
- CVE-2019-12133Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services assoc...7.8
Product normalization is registry-driven with AI assist and human review. How it works