Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Manageengine

First CVE: Mar 24, 2007Active for: 19 yearsTotal CVEs: 89
47.6
VTI Score
High

ManageEngine operates a portfolio of IT management and administration tools including ServiceDesk Plus, Applications Manager, Desktop Central, and Password Manager Pro, many of which are deployed in security-critical roles across enterprises. The vendor's vulnerability footprint, though concentrated in a focused set of products, ranks among the more prominent in the landscape, reflecting the widespread adoption and administrative privileges these tools command. Vulnerabilities recur consistently through web-application and authentication layers—notably cross-site scripting, path traversal, SQL injection, sensitive information exposure, and improper authentication—reflecting the data-handling and access-control demands of centralized management platforms. The vendor's disclosures frequently acquire public exploit code, underscoring the appeal of administrative tools as targets for post-breach lateral movement and privilege escalation. Defenders should prioritize inventory and network segmentation for these products and treat their patch cycles as operationally urgent; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
89
Total CVEs
More Total CVEs than 99% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Manageengine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 24, 2007
19 years ago
Most Recent CVE
Jul 23, 2025
366 days ago

Products(20 total)

Top CVEs

Signals from CVEs in this vendor scope (89 CVEs).

89 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-5301HIGH
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
Aug 28, 20178.884NOYES
CVE-2015-8249CRITICAL
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
Sep 28, 20179.881NOYES
CVE-2017-11512HIGH
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot UR
Nov 8, 20177.578NOYES
CVE-2014-5377MEDIUM
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
Sep 4, 20145.069NOYES
CVE-2014-3996HIGH
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 9004
Dec 5, 20147.556NOYES
CVE-2011-2757MEDIUM
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in th
Jul 17, 20115.055NOYES
CVE-2014-8499MEDIUM
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remot
Nov 17, 20146.552NOYES
CVE-2011-2755MEDIUM
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remote attackers to read arbitrary files via unspecified vectors
Jul 17, 20115.042NOYES
CVE-2024-24409HIGH
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
Nov 8, 20248.839NOYES
CVE-2016-9488CRITICAL
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /ser
Jun 5, 20189.839NOYES
View all 89 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products89 CVEs
44%
52%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.2%)
Network52 (58.4%)
Unknown35 (39.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (59.6%)
High1 (1.1%)
Unknown35 (39.3%)
User Interaction
None47 (52.8%)
Unknown35 (39.3%)
Required7 (7.9%)
Privileges Required
Low41 (46.1%)
High3 (3.4%)
None10 (11.2%)
Unknown35 (39.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (89 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
6.7% of CVEs· 98th percentile
Nuclei
2 CVEs
2.2% of CVEs· 95th percentile
ExploitDB
18 CVEs
20.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Manageengine.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Manageengine — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Manageengine's Products

View all 4 CNAs →

Top CWEs