Manageengine Admanager Plus
Vendor:
First CVE: Nov 23, 2011 · Active for 14 years
53
Total CVEs
More Total CVEs than 98% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
1.9%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Manageengine Admanager Plus over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 23, 2011
14 years ago
Most Recent CVE
Jan 13, 2026
196 days ago
CVE Severity & Scoring
Manageengine Admanager Plus53 CVEs
30%
28%
42%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (5.7%)
Network48 (90.6%)
Unknown2 (3.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low49 (92.5%)
High2 (3.8%)
Unknown2 (3.8%)
User Interaction
None43 (81.1%)
Unknown2 (3.8%)
Required8 (15.1%)
Privileges Required
Low15 (28.3%)
High5 (9.4%)
None31 (58.5%)
Unknown2 (3.8%)
Top CVEs
Signals from CVEs in this product scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47966CRITICAL Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java | Jan 18, 2023 | 9.8 | 99 | YES | YES |
CVE-2023-29084HIGH Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings. | Apr 13, 2023 | 7.2 | 89 | NO | YES |
CVE-2021-37539CRITICAL Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. | Sep 27, 2021 | 9.8 | 79 | NO | NO |
CVE-2021-37926CRITICAL Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | Oct 7, 2021 | 9.8 | 70 | NO | NO |
CVE-2021-37918CRITICAL Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | Oct 7, 2021 | 9.8 | 70 | NO | NO |
CVE-2022-42904HIGH Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings. | Nov 18, 2022 | 7.2 | 69 | NO | NO |
CVE-2021-20130HIGH ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface. | Oct 13, 2021 | 8.8 | 44 | NO | NO |
CVE-2022-29457HIGH Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path confi | Apr 18, 2022 | 8.8 | 43 | NO | YES |
CVE-2024-24409HIGH Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | Nov 8, 2024 | 8.8 | 39 | NO | YES |
CVE-2021-20131HIGH ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface. | Oct 13, 2021 | 8.8 | 36 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (53 CVEs).
CISA KEV
1 CVE
1.9% of CVEs· 98th percentile
Metasploit
2 CVEs
3.8% of CVEs· 97th percentile
Nuclei
2 CVEs
3.8% of CVEs· 97th percentile
ExploitDB
4 CVEs
7.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (53 CVEs).
Media Mentions
Signals from CVEs in this product scope (53 CVEs).
Top CNAs Publishing CVEs For Manageengine Admanager Plus
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 2 | 6.5 | 2.5% | 0 | 0 |
| 7.2 | 8 | 7.1 | 1.7% | 0 | 1 |
| 7.1 | 32 | 8.1 | 31.7% | 1 | 4 |
| 7.0 | 3 | 8.0 | 4.7% | 0 | 1 |
| 6.6.5 | 2 | 8.1 | 4.3% | 0 | 1 |
| 6.6 | 3 | 8.6 | 2.4% | 0 | 2 |
| 6.5.7 | 2 | 7.5 | 5.0% | 0 | 2 |
| 6.2 | 1 | 8.8 | 3.9% | 0 | 1 |
| 6.1 | 4 | 8.2 | 3.3% | 0 | 1 |
| 4.4.0 | 1 | 4.3 | 3.1% | 0 | 0 |