Manageengine Admanager Plus

Vendor:

First CVE: Nov 23, 2011 · Active for 14 years

53
Total CVEs
More Total CVEs than 98% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Manageengine Admanager Plus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2011
14 years ago
Most Recent CVE
Jan 13, 2026
196 days ago

CVE Severity & Scoring

Manageengine Admanager Plus53 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local3 (5.7%)
Network48 (90.6%)
Unknown2 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (92.5%)
High2 (3.8%)
Unknown2 (3.8%)
User Interaction
None43 (81.1%)
Unknown2 (3.8%)
Required8 (15.1%)
Privileges Required
Low15 (28.3%)
High5 (9.4%)
None31 (58.5%)
Unknown2 (3.8%)

Top CVEs

Signals from CVEs in this product scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java
Jan 18, 20239.899YESYES
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
Apr 13, 20237.289NOYES
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
Sep 27, 20219.879NONO
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Oct 7, 20219.870NONO
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
Oct 7, 20219.870NONO
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
Nov 18, 20227.269NONO
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
Oct 13, 20218.844NONO
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path confi
Apr 18, 20228.843NOYES
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
Nov 8, 20248.839NOYES
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.
Oct 13, 20218.836NONO

Exploit Exposure

Signals from CVEs in this product scope (53 CVEs).

CISA KEV
1 CVE
1.9% of CVEs· 98th percentile
Metasploit
2 CVEs
3.8% of CVEs· 97th percentile
Nuclei
2 CVEs
3.8% of CVEs· 97th percentile
ExploitDB
4 CVEs
7.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (53 CVEs).

Media Mentions

Signals from CVEs in this product scope (53 CVEs).

Top CNAs Publishing CVEs For Manageengine Admanager Plus

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.026.52.5%00
7.287.11.7%01
7.1328.131.7%14
7.038.04.7%01
6.6.528.14.3%01
6.638.62.4%02
6.5.727.55.0%02
6.218.83.9%01
6.148.23.3%01
4.4.014.33.1%00