cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-5471,https://securityvulnerability.io/vulnerability/CVE-2024-5471,Agent Takeover Vulnerability in DDI Central Versions 4001 and Prior,"An agent takeover vulnerability exists in Zohocorp's ManageEngine DDI Central, affecting versions 4001 and prior. This vulnerability arises from the presence of hard-coded sensitive keys, which could potentially allow unauthorized access and control over the affected systems. By exploiting this weakness, attackers could manipulate network configurations or access sensitive information, putting organizations at risk. It is crucial for users of ManageEngine DDI Central to review their current versions and implement necessary security measures to mitigate this risk.",Manageengine,Ddi Central,9.8,CRITICAL,0.0340300016105175,false,,false,false,false,,,false,false,,2024-07-17T10:56:53.675Z,0 CVE-2024-38868,https://securityvulnerability.io/vulnerability/CVE-2024-38868,Incorrect Authorization Vulnerability Affects Zohocorp's Endpoint Central,"An incorrect authorization vulnerability exists in Zohocorp's ManageEngine Endpoint Central, which compromises the isolation capabilities of devices. This flaw allows unauthorized users to potentially interact with isolated endpoints, posing significant security risks. Affected versions are those prior to 11.3.2406.08 and 11.3.2400.15, emphasizing the importance of timely updates to safeguard against exploitation.",Manageengine,Endpoint Central,8.3,HIGH,0.02012000046670437,false,,false,false,false,,,false,false,,2024-08-30T17:44:38.932Z,0