Zohocorp Manageengine Adaudit Plus vulnerabilities

52 known vulnerabilities affecting zohocorp/manageengine_adaudit_plus.

Total CVEs
52
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH38MEDIUM5LOW1

Vulnerabilities

Page 1 of 3
CVE-2025-41444HIGHCVSS 8.3fixed in 8.5v8.52025-06-09
CVE-2025-41444 [HIGH] CWE-89 CVE-2025-41444: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
nvd
CVE-2025-36528HIGHCVSS 8.3fixed in 8.5v8.52025-06-09
CVE-2025-36528 [HIGH] CWE-89 CVE-2025-36528: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
nvd
CVE-2025-27709HIGHCVSS 8.3fixed in 8.5v8.52025-06-09
CVE-2025-27709 [HIGH] CWE-89 CVE-2025-27709: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.
nvd
CVE-2025-41407HIGHCVSS 8.3fixed in 8.5v8.52025-05-23
CVE-2025-41407 [HIGH] CWE-89 CVE-2025-41407: Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU His Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
nvd
CVE-2025-36527HIGHCVSS 8.3fixed in 8.5v8.52025-05-23
CVE-2025-36527 [HIGH] CWE-89 CVE-2025-36527: Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporti Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
nvd
CVE-2025-41403HIGHCVSS 8.3fixed in 8.5v8.52025-05-22
CVE-2025-41403 [HIGH] CWE-89 CVE-2025-41403: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
nvd
CVE-2025-3836HIGHCVSS 8.3fixed in 8.5v8.52025-05-22
CVE-2025-3836 [HIGH] CWE-89 CVE-2025-3836: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
nvd
CVE-2025-3834HIGHCVSS 8.1fixed in 8.5v8.52025-05-14
CVE-2025-3834 [HIGH] CWE-89 CVE-2025-3834: Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
nvd
CVE-2024-49574HIGHCVSS 8.8fixed in 8.1v8.12024-11-18
CVE-2024-49574 [HIGH] CWE-89 CVE-2024-49574: Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the report Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.
nvd
CVE-2024-36485HIGHCVSS 8.8fixed in 8.1v8.12024-11-04
CVE-2024-36485 [HIGH] CWE-89 CVE-2024-36485: Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.
nvd
CVE-2024-5608HIGHCVSS 8.1fixed in 8.1v8.12024-10-24
CVE-2024-5608 [HIGH] CWE-89 CVE-2024-5608: Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the techni Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
nvd
CVE-2024-5586HIGHCVSS 8.8≤ 8.0v8.12024-08-23
CVE-2024-5586 [HIGH] CWE-89 CVE-2024-5586: Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.
nvd
CVE-2024-5490HIGHCVSS 8.8fixed in 8.02024-08-23
CVE-2024-5490 [HIGH] CWE-89 CVE-2024-5490: Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.
nvd
CVE-2024-36517HIGHCVSS 8.8fixed in 8.02024-08-23
CVE-2024-36517 [HIGH] CWE-89 CVE-2024-36517: Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.
nvd
CVE-2024-5467HIGHCVSS 8.8≤ 8.0v8.12024-08-23
CVE-2024-5467 [HIGH] CWE-89 CVE-2024-5467: Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.
nvd
CVE-2024-36514HIGHCVSS 8.8fixed in 8.02024-08-23
CVE-2024-36514 [HIGH] CWE-89 CVE-2024-36514: Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.
nvd
CVE-2024-36516HIGHCVSS 8.8fixed in 8.02024-08-23
CVE-2024-36516 [HIGH] CVE-2024-36516: Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which have affected ADAudit Plus' dashboard.
nvd
CVE-2024-5556HIGHCVSS 8.8fixed in 8.02024-08-23
CVE-2024-5556 [HIGH] CWE-89 CVE-2024-5556: Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.
nvd
CVE-2024-36515HIGHCVSS 8.8fixed in 8.02024-08-23
CVE-2024-36515 [HIGH] CWE-89 CVE-2024-36515: Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injec Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which have affected ADAudit Plus' dashboard.
nvd
CVE-2024-36034HIGHCVSS 8.8fixed in 8.0v8.02024-08-12
CVE-2024-36034 [HIGH] CWE-89 CVE-2024-36034: Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.
nvd