CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

zohocorp

manageengine_servicedesk_plus

10 known vulnerabilities · sorted by CVSS score

CVE-2021-44077
CRITICAL9.8

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

zohocorp / manageengine_servicedesk_plus+72
Network
Published Nov 29, 2021
CVE-2021-44526
CRITICAL9.8

Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.

zohocorp / manageengine_servicedesk_plus+364
Network
Published Dec 23, 2021
CVE-2021-37415
CRITICAL9.8

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

zohocorp / manageengine_servicedesk_plus+64
Network
Published Sep 1, 2021
CVE-2020-35682
HIGH8.8

Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

zohocorp / manageengine_servicedesk_plus+34
Network
Published Mar 13, 2021
CVE-2021-31160
HIGH7.5

Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.

zohocorp / manageengine_servicedesk_plus+22
Network
Published Jun 29, 2021
CVE-2020-14048
HIGH7.5

Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.

zohocorp / manageengine_servicedesk_plus+268
Network
Published Jun 12, 2020
CVE-2021-20081
HIGH7.2

Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.

zohocorp / manageengine_servicedesk_plus+5
Network
Published Jun 10, 2021
CVE-2020-13154
MEDIUM6.5

Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

zohocorp / manageengine_servicedesk_plus+12
Network
Published May 18, 2020
CVE-2019-15083
MEDIUM6.1

Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine ServiceDesk administrator side. At "Asset Home > Server > <workstation> > software" the administrator of ManageEngine can control what software is installed on the workstation. This table shows all the installed program names in the Software column. In this field, a remote attacker can inject malicious code in order to execute it when the ManageEngine administrator visualizes this page.

zohocorp / manageengine_servicedesk_plus+22
Network
Published May 14, 2020
CVE-2021-20080
MEDIUM6.1

Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.

zohocorp / manageengine_servicedesk_plus+275
Network
Published Apr 9, 2021