Vendor CVEs
Zoho
All CVEs
422 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40172 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. | ||
| CVE-2020-12116 | Hig | 0.57 | 7.5 | 0.97 | May 7, 2020 | Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request. | ||
| CVE-2019-11361 | Hig | 0.57 | 8.8 | 0.03 | Mar 19, 2020 | Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover. | ||
| CVE-2020-9346 | Hig | 0.57 | 8.8 | 0.02 | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role. | ||
| CVE-2019-18411 | Hig | 0.57 | 8.8 | 0.02 | Nov 6, 2019 | Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the… | ||
| CVE-2019-15645 | Hig | 0.57 | 8.8 | 0.01 | Aug 27, 2019 | The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | ||
| CVE-2019-12959 | Hig | 0.57 | 8.8 | 0.03 | Aug 8, 2019 | Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter. | ||
| CVE-2019-5963 | Hig | 0.57 | 8.8 | 0.01 | Jul 5, 2019 | Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | ||
| CVE-2017-11740 | Hig | 0.57 | 8.8 | 0.03 | May 23, 2019 | In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the… | ||
| CVE-2018-13411 | Hig | 0.57 | 8.8 | 0.03 | Sep 12, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. | ||
| CVE-2017-17552 | Hig | 0.57 | 8.8 | 0.02 | Feb 7, 2018 | /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted. | ||
| CVE-2016-4889 | Hig | 0.57 | 8.8 | 0.03 | Apr 14, 2017 | ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions. | ||
| CVE-2019-14693 | Hig | 0.56 | 8.5 | 0.04 | Aug 8, 2019 | Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | ||
| CVE-2024-37225 | Hig | 0.55 | 8.5 | 0.00 | Jul 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Automation.This issue affects Zoho Marketing Automation: from n/a through 1.2.7. | ||
| CVE-2023-28342 | Hig | 0.55 | 7.5 | 0.78 | Apr 5, 2023 | Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API. | ||
| CVE-2017-11512 | Hig | 0.55 | 7.5 | 0.80 | Nov 8, 2017 | The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files. | ||
| CVE-2023-49335 | Hig | 0.54 | 8.3 | 0.03 | May 20, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details. | ||
| CVE-2023-49334 | Hig | 0.54 | 8.3 | 0.03 | May 20, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report. | ||
| CVE-2023-49333 | Hig | 0.54 | 8.3 | 0.03 | May 20, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature. | ||
| CVE-2023-49332 | Hig | 0.54 | 8.3 | 0.03 | May 20, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares. | ||
| CVE-2023-49331 | Hig | 0.54 | 8.3 | 0.03 | May 20, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option. | ||
| CVE-2023-49330 | Hig | 0.54 | 8.3 | 0.02 | May 20, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data. | ||
| CVE-2024-21775 | Hig | 0.54 | 8.3 | 0.05 | Feb 16, 2024 | Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature. | ||
| CVE-2018-16364 | Hig | 0.54 | 8.1 | 0.18 | Sep 26, 2018 | A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share. | ||
| CVE-2018-17283 | Hig | 0.54 | 7.5 | 0.66 | Sep 21, 2018 | Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or… | ||
| CVE-2023-48646 | Hig | 0.53 | 7.2 | 0.82 | Nov 22, 2023 | Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings. | ||
| CVE-2023-35785 | Hig | 0.53 | 8.1 | 0.02 | Aug 28, 2023 | Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and… | ||
| CVE-2022-40770 | Hig | 0.53 | 7.2 | 0.81 | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users. | ||
| CVE-2020-15589 | Hig | 0.53 | 8.1 | 0.08 | Oct 2, 2020 | A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server… | ||
| CVE-2020-14008 | Hig | 0.53 | 7.2 | 0.40 | Sep 4, 2020 | Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution. | ||
| CVE-2020-11946 | Hig | 0.53 | 7.5 | 0.52 | Apr 20, 2020 | Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. | ||
| CVE-2017-11738 | Hig | 0.53 | 8.1 | 0.04 | May 23, 2019 | In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack. | ||
| CVE-2020-13818 | Hig | 0.52 | 7.5 | 0.37 | Jun 4, 2020 | In Zoho ManageEngine OpManager before 125144, when is used, directory traversal validation can be bypassed. | ||
| CVE-2023-26601 | Hig | 0.51 | 7.5 | 0.34 | Mar 6, 2023 | Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS). | ||
| CVE-2022-41339 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2022 | In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation. | ||
| CVE-2021-44652 | Hig | 0.51 | 7.8 | 0.03 | Jan 12, 2022 | Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component. | ||
| CVE-2021-46165 | Hig | 0.51 | 7.8 | 0.00 | Jan 10, 2022 | Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. | ||
| CVE-2021-42954 | Hig | 0.51 | 7.8 | 0.00 | Nov 17, 2021 | Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users),… | ||
| CVE-2021-42956 | Hig | 0.51 | 7.8 | 0.01 | Nov 17, 2021 | Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely,… | ||
| CVE-2020-9367 | Hig | 0.51 | 7.8 | 0.01 | Mar 18, 2021 | The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the… | ||
| CVE-2019-17421 | Hig | 0.51 | 7.8 | 0.01 | Nov 21, 2019 | Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload. | ||
| CVE-2019-12133 | Hig | 0.51 | 7.8 | 0.02 | Jun 18, 2019 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current… | ||
| CVE-2018-18980 | Hig | 0.51 | 7.5 | 0.25 | Nov 6, 2018 | An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local… | ||
| CVE-2018-13412 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2018 | An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version. | ||
| CVE-2020-11527 | Hig | 0.50 | 7.5 | 0.09 | Apr 4, 2020 | In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files. | ||
| CVE-2020-8509 | Hig | 0.50 | 7.5 | 0.10 | Mar 30, 2020 | Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure. | ||
| CVE-2024-47334 | Hig | 0.49 | 7.6 | 0.00 | Oct 9, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1. | ||
| CVE-2023-32783 | Hig | 0.49 | 7.5 | 0.04 | Aug 7, 2023 | The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour." | ||
| CVE-2023-22624 | Hig | 0.49 | 7.5 | 0.03 | Jan 17, 2023 | Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. | ||
| CVE-2020-21641 | Hig | 0.49 | 7.5 | 0.04 | Aug 15, 2022 | Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file. |
- risk 0.57cvss 8.8epss 0.01
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
- risk 0.57cvss 7.5epss 0.97
Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.
- risk 0.57cvss 8.8epss 0.03
Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.
- risk 0.57cvss 8.8epss 0.02
Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.
- risk 0.57cvss 8.8epss 0.02
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the…
- risk 0.57cvss 8.8epss 0.01
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
- risk 0.57cvss 8.8epss 0.03
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
- risk 0.57cvss 8.8epss 0.03
In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the…
- risk 0.57cvss 8.8epss 0.03
An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
- risk 0.57cvss 8.8epss 0.02
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
- risk 0.57cvss 8.8epss 0.03
ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.
- risk 0.56cvss 8.5epss 0.04
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
- risk 0.55cvss 8.5epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Automation.This issue affects Zoho Marketing Automation: from n/a through 1.2.7.
- risk 0.55cvss 7.5epss 0.78
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
- risk 0.55cvss 7.5epss 0.80
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.
- risk 0.54cvss 8.3epss 0.03
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
- risk 0.54cvss 8.3epss 0.03
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.
- risk 0.54cvss 8.3epss 0.03
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.
- risk 0.54cvss 8.3epss 0.03
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
- risk 0.54cvss 8.3epss 0.03
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
- risk 0.54cvss 8.3epss 0.02
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.
- risk 0.54cvss 8.3epss 0.05
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
- risk 0.54cvss 8.1epss 0.18
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.
- risk 0.54cvss 7.5epss 0.66
Zoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a /oputilsServlet?action=getAPIKey request that can be leveraged against Firewall Analyzer to add an admin user via /api/json/v2/admin/addUser or…
- risk 0.53cvss 7.2epss 0.82
Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.
- risk 0.53cvss 8.1epss 0.02
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and…
- risk 0.53cvss 7.2epss 0.81
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
- risk 0.53cvss 8.1epss 0.08
A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server…
- risk 0.53cvss 7.2epss 0.40
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
- risk 0.53cvss 7.5epss 0.52
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
- risk 0.53cvss 8.1epss 0.04
In Zoho ManageEngine Application Manager prior to 14.6 Build 14660, the 'haid' parameter of the '/auditLogAction.do' module is vulnerable to a Time-based Blind SQL Injection attack.
- risk 0.52cvss 7.5epss 0.37
In Zoho ManageEngine OpManager before 125144, when is used, directory traversal validation can be bypassed.
- risk 0.51cvss 7.5epss 0.34
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
- risk 0.51cvss 7.8epss 0.01
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
- risk 0.51cvss 7.8epss 0.03
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
- risk 0.51cvss 7.8epss 0.00
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
- risk 0.51cvss 7.8epss 0.00
Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows Everyone user group (non-admin or any guest users),…
- risk 0.51cvss 7.8epss 0.01
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely,…
- risk 0.51cvss 7.8epss 0.01
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the…
- risk 0.51cvss 7.8epss 0.01
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
- risk 0.51cvss 7.8epss 0.02
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current…
- risk 0.51cvss 7.5epss 0.25
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the RequestXML parameter in a /devices/ProcessRequest.do GET request. For example, the attacker can trigger the transmission of local…
- risk 0.51cvss 7.8epss 0.01
An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.
- risk 0.50cvss 7.5epss 0.09
In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
- risk 0.50cvss 7.5epss 0.10
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
- risk 0.49cvss 7.6epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Flow Zoho Flow zoho-flow allows SQL Injection.This issue affects Zoho Flow: from n/a through <= 2.7.1.
- risk 0.49cvss 7.5epss 0.04
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
- risk 0.49cvss 7.5epss 0.03
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
- risk 0.49cvss 7.5epss 0.04
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.
Page 4 of 9