Applications Manager

Vendor:

First CVE: Jan 29, 2008 · Active for 18 years

11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Applications Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2008
18 years ago
Most Recent CVE
Jul 23, 2025
366 days ago

CVE Severity & Scoring

Applications Manager11 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network5 (45.5%)
Unknown6 (54.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (45.5%)
High0 (0.0%)
Unknown6 (54.5%)
User Interaction
None3 (27.3%)
Unknown6 (54.5%)
Required2 (18.2%)
Privileges Required
Low1 (9.1%)
High2 (18.2%)
None2 (18.2%)
Unknown6 (54.5%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /ser
Jun 5, 20189.839NOYES
Multiple SQL injection vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to execute arbitrary SQL commands via the (1) viewId parameter to fa
Feb 14, 20127.523NONO
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 8.1 build 8100 allow remote attackers to inject arbitrary web script or HTML via the (1) sh
Jan 29, 20084.321NOYES
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.
Jan 29, 20256.520NONO
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
Jul 23, 20255.419NONO
ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote attackers to obtain sensitive inf
Jan 29, 20086.419NONO
Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.
Aug 1, 20244.718NONO
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Sc
Jun 5, 20186.118NONO
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Applications Manager 9.x and 10.x allow remote attackers to inject arbitrary web script or HTML via the (1) peri
Feb 14, 20124.317NONO
ManageEngine Applications Manager 8.1 build 8100 allows remote attackers to obtain sensitive information ( Home->Summary) via an invalid URI, as demonstrated by the "/-" URI. NOTE
Jan 29, 20085.015NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
18.2% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Applications Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.525.91.3%00
9.425.91.3%00
9.325.91.3%00
9.225.91.3%00
9.125.91.3%00
914.31.4%00
8.214.31.0%00
8.1_build_810035.21.3%01
8.114.31.0%00
13.028.03.3%01
12.028.03.3%01
10.325.91.3%00
10.225.91.3%00
10.125.91.3%00
10.025.91.3%00