Vendor CVEs
Zoho
All CVEs
422 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15588 | Cri | 0.65 | 9.8 | 0.13 | Jul 29, 2020 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code… | ||
| CVE-2020-11518 | Cri | 0.65 | 9.8 | 0.19 | Apr 4, 2020 | Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. | ||
| CVE-2020-10541 | Cri | 0.65 | 9.8 | 0.10 | Mar 13, 2020 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108. | ||
| CVE-2020-8540 | Cri | 0.65 | 9.8 | 0.13 | Mar 11, 2020 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. | ||
| CVE-2019-3905 | Cri | 0.65 | 10.0 | 0.03 | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. | ||
| CVE-2018-20338 | Cri | 0.65 | 9.8 | 0.12 | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. | ||
| CVE-2018-18475 | Cri | 0.65 | 9.8 | 0.20 | Oct 23, 2018 | Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. | ||
| CVE-2017-16851 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. | ||
| CVE-2017-16850 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. | ||
| CVE-2017-16849 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. | ||
| CVE-2017-16848 | Cri | 0.65 | 9.8 | 0.15 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. | ||
| CVE-2017-16847 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action. | ||
| CVE-2017-16846 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. | ||
| CVE-2023-48793 | Cri | 0.64 | 9.8 | 0.07 | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | ||
| CVE-2023-48792 | Cri | 0.64 | 9.8 | 0.07 | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | ||
| CVE-2023-35854 | Cri | 0.64 | 9.8 | 0.06 | Jun 20, 2023 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is… | ||
| CVE-2023-31099 | Hig | 0.64 | 8.8 | 0.82 | May 4, 2023 | Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. | ||
| CVE-2020-21642 | Cri | 0.64 | 9.8 | 0.07 | Aug 15, 2022 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code. | ||
| CVE-2022-36412 | Cri | 0.64 | 9.8 | 0.05 | Jul 26, 2022 | In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.) | ||
| CVE-2022-24306 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. | ||
| CVE-2022-24305 | Cri | 0.64 | 9.8 | 0.03 | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. | ||
| CVE-2021-44526 | Cri | 0.64 | 9.8 | 0.03 | Dec 23, 2021 | Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. | ||
| CVE-2021-44525 | Cri | 0.64 | 9.8 | 0.03 | Dec 20, 2021 | Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required. | ||
| CVE-2021-44676 | Cri | 0.64 | 9.8 | 0.04 | Dec 20, 2021 | Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state. | ||
| CVE-2021-44675 | Cri | 0.64 | 9.8 | 0.06 | Dec 20, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required. | ||
| CVE-2021-44514 | Cri | 0.64 | 9.8 | 0.05 | Dec 9, 2021 | OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. | ||
| CVE-2021-42099 | Cri | 0.64 | 9.8 | 0.07 | Nov 30, 2021 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. | ||
| CVE-2021-42002 | Cri | 0.64 | 9.8 | 0.07 | Nov 11, 2021 | Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution. | ||
| CVE-2021-41833 | Cri | 0.64 | 9.8 | 0.08 | Nov 11, 2021 | Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. | ||
| CVE-2021-41080 | Cri | 0.64 | 9.8 | 0.04 | Nov 11, 2021 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search. | ||
| CVE-2020-24743 | Cri | 0.64 | 9.8 | 0.03 | Nov 3, 2021 | An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter. | ||
| CVE-2021-41075 | Cri | 0.64 | 9.8 | 0.03 | Oct 13, 2021 | The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API. | ||
| CVE-2021-38298 | Cri | 0.64 | 9.8 | 0.03 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. | ||
| CVE-2021-37931 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37930 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37929 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37928 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37762 | Cri | 0.64 | 9.8 | 0.08 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. | ||
| CVE-2021-37761 | Cri | 0.64 | 9.8 | 0.10 | Sep 27, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. | ||
| CVE-2021-37927 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. | ||
| CVE-2021-28960 | Cri | 0.64 | 9.8 | 0.02 | Sep 21, 2021 | Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations. | ||
| CVE-2021-37422 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. | ||
| CVE-2021-37423 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. | ||
| CVE-2021-37421 | Cri | 0.64 | 9.8 | 0.02 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. | ||
| CVE-2021-37417 | Cri | 0.64 | 9.8 | 0.05 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. | ||
| CVE-2021-40177 | Cri | 0.64 | 9.8 | 0.05 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. | ||
| CVE-2021-40175 | Cri | 0.64 | 9.8 | 0.07 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. | ||
| CVE-2021-33911 | Cri | 0.64 | 9.8 | 0.05 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. | ||
| CVE-2021-31531 | Cri | 0.64 | 9.8 | 0.02 | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). | ||
| CVE-2020-29658 | Cri | 0.64 | 9.8 | 0.04 | Mar 5, 2021 | Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation. |
- risk 0.65cvss 9.8epss 0.13
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code…
- risk 0.65cvss 9.8epss 0.19
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
- risk 0.65cvss 9.8epss 0.10
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
- risk 0.65cvss 9.8epss 0.13
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
- risk 0.65cvss 10.0epss 0.03
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
- risk 0.65cvss 9.8epss 0.12
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
- risk 0.65cvss 9.8epss 0.20
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
- risk 0.65cvss 9.8epss 0.15
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
- risk 0.64cvss 9.8epss 0.06
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…
- risk 0.64cvss 8.8epss 0.82
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
- risk 0.64cvss 9.8epss 0.07
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
- risk 0.64cvss 9.8epss 0.05
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
- risk 0.64cvss 9.8epss 0.06
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
- risk 0.64cvss 9.8epss 0.05
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.
- risk 0.64cvss 9.8epss 0.03
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
- risk 0.64cvss 9.8epss 0.03
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
Page 2 of 9