CVE Tools

Manageengine Desktop Central

50 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Manageengine Desktop Central, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Manageengine Desktop Central CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Manageengine Desktop Central CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 50 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical2142%
  • High1734%
  • Medium1224%

Latest CVEs

The 15 most recently published vulnerabilities affecting Manageengine Desktop Central.

  1. CVE-2023-4769Server-Side Request Forgery in ManageEngine Desktop Central6.6
  2. CVE-2023-4768Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central6.1
  3. CVE-2023-4767Improper Neutralization of CRLF Sequences in ManageEngine Desktop Central6.1
  4. CVE-2022-48362Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbit...8.8
  5. CVE-2022-23779Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.5.3
  6. CVE-2022-23863Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.6.5
  7. CVE-2021-44757Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP a...9.1
  8. CVE-2021-46164Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.8.8
  9. CVE-2021-46165Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.7.8
  10. CVE-2021-46166Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.6.5
  11. CVE-2021-44515Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127....9.8
  12. CVE-2021-37414Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.7.5
  13. CVE-2020-9367The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the compl...7.8
  14. CVE-2020-28050Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.9.1
  15. CVE-2019-16962Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store