Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2022-28810 | Zoho | ManageEngine | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. | 6.8 CISA | 2023-03-07 | 2023-03-28 | Unknown |
| CVE-2022-47966 | Zoho | ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario. | 9.8 CISA | 2023-01-23 | 2023-02-13 | Known |
| CVE-2022-35405 | Zoho | ManageEngine | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution. | 9.8 CISA | 2022-09-22 | 2022-10-13 | Unknown |
| CVE-2021-44515 | Zoho | Desktop Central | Zoho Desktop Central Authentication Bypass Vulnerability Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server. | 9.8 CISA | 2021-12-10 | 2021-12-24 | Unknown |
| CVE-2021-44077 | Zoho | ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus | Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution | 9.8 CISA | 2021-12-01 | 2021-12-15 | Unknown |
| CVE-2021-37415 | Zoho | ManageEngine ServiceDesk Plus (SDP) | Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication | 9.8 CISA | 2021-12-01 | 2021-12-15 | Unknown |
| CVE-2019-8394 | Zoho | ManageEngine | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. | 7.5 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-10189 | Zoho | ManageEngine | Zoho ManageEngine Desktop Central File Upload Vulnerability Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. | 9.8 CNA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2021-40539 | Zoho | ManageEngine | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. | 9.8 CISA | 2021-11-03 | 2021-11-17 | Known |