VYPR

Vendor CVEs

Zoho

All CVEs

422 total · sorted by risk
  • CVE-2022-36923HigAug 10, 2022
    risk 0.49cvss 7.5epss 0.07

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and…

  • CVE-2022-35403HigJul 12, 2022
    risk 0.49cvss 7.5epss 0.06

    Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with…

  • CVE-2022-34829HigJul 4, 2022
    risk 0.49cvss 7.5epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.

  • CVE-2022-32551HigJul 2, 2022
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).

  • CVE-2021-43296HigNov 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.

  • CVE-2021-41829HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.

  • CVE-2021-41828HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.

  • CVE-2021-41827HigSep 30, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.

  • CVE-2021-37419HigSep 21, 2021
    risk 0.49cvss 7.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

  • CVE-2021-37414HigSep 10, 2021
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.

  • CVE-2021-31530HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.03

    Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.

  • CVE-2021-31160HigJun 29, 2021
    risk 0.49cvss 7.5epss 0.04

    Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.

  • CVE-2020-10816HigOct 8, 2020
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine Applications Manager 14780 and before allows a remote unauthenticated attacker to register managed servers via AAMRequestProcessor servlet.

  • CVE-2020-24397HigOct 2, 2020
    risk 0.49cvss 7.2epss 0.28

    An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code…

  • CVE-2020-14048HigJun 12, 2020
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents.

  • CVE-2019-15046HigAug 14, 2019
    risk 0.49cvss 7.5epss 0.05

    Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.

  • CVE-2017-11559HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.04

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.

  • CVE-2018-19374HigApr 30, 2019
    risk 0.49cvss 7.0epss 0.01

    Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.

  • CVE-2019-7161HigMar 21, 2019
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data.

  • CVE-2018-19118HigDec 13, 2018
    risk 0.49cvss 7.5epss 0.07

    Zoho ManageEngine ADAudit before 5.1 build 5120 allows remote attackers to cause a denial of service (stack-based buffer overflow) via the 'Domain Name' field when adding a new domain.

  • CVE-2018-12999HigJun 29, 2018
    risk 0.49cvss 7.5epss 0.09

    Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon…

  • CVE-2018-12997HigJun 29, 2018
    risk 0.49cvss 7.5epss 0.07

    Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers…

  • CVE-2017-11511HigNov 8, 2017
    risk 0.49cvss 7.5epss 0.04

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

  • CVE-2025-1724HigMar 17, 2025
    risk 0.48cvss 7.4epss 0.01

    Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.

  • CVE-2023-38743HigSep 11, 2023
    risk 0.48cvss 7.2epss 0.12

    Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.

  • CVE-2023-28341MedApr 11, 2023
    risk 0.48cvss 6.1epss 0.99

    Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.

  • CVE-2019-12876HigJul 17, 2019
    risk 0.48cvss 7.3epss 0.05

    Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.

  • CVE-2018-12998MedJun 29, 2018
    risk 0.48cvss 6.1epss 0.99

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote…

  • CVE-2022-42904HigNov 18, 2022
    risk 0.47cvss 7.2epss 0.83

    Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.

  • CVE-2021-44650HigJan 12, 2022
    risk 0.47cvss 7.2epss 0.05

    Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.

  • CVE-2021-42955HigNov 17, 2021
    risk 0.47cvss 7.3epss 0.00

    Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server…

  • CVE-2019-19034HigMar 23, 2020
    risk 0.47cvss 7.2epss 0.06

    Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT…

  • CVE-2018-5342HigApr 18, 2018
    risk 0.47cvss 7.2epss 0.04

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account.

  • CVE-2018-5340HigApr 18, 2018
    risk 0.47cvss 7.2epss 0.05

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries).

  • CVE-2025-49028HigDec 31, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Zoho Mail Zoho ZeptoMail transmail allows Stored XSS.This issue affects Zoho ZeptoMail: from n/a through <= 3.3.1.

  • CVE-2024-38696HigJul 20, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zoho CRM Zoho CRM Lead Magnet allows Reflected XSS.This issue affects Zoho CRM Lead Magnet: from n/a through 1.7.8.8.

  • CVE-2023-23074MedFeb 1, 2023
    risk 0.46cvss 6.1epss 0.84

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.

  • CVE-2022-47578HigDec 20, 2022
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the…

  • CVE-2022-47577HigDec 20, 2022
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15. Despite configuring complete restrictions on USB pendrives, USB HDD devices, memory cards, USB connections to mobile devices, etc., it is still possible to bypass the…

  • CVE-2019-12252MedMay 21, 2019
    risk 0.46cvss 6.5epss 0.08

    In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.

  • CVE-2018-16833MedSep 21, 2018
    risk 0.45cvss 6.1epss 0.65

    Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

  • CVE-2019-12476MedJun 17, 2019
    risk 0.44cvss 6.8epss 0.02

    An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence…

  • CVE-2019-8929MedMay 17, 2019
    risk 0.44cvss 6.1epss 0.11

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/selectDevice.jsp file in these GET parameters: param and rtype.

  • CVE-2023-31492MedAug 17, 2023
    risk 0.43cvss 6.5epss 0.05

    Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

  • CVE-2023-28340MedApr 11, 2023
    risk 0.43cvss 6.5epss 0.03

    Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

  • CVE-2019-15083MedMay 14, 2020
    risk 0.43cvss 6.1epss 0.06

    Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local administrator can execute code on the Manage Engine…

  • CVE-2020-10859MedMay 5, 2020
    risk 0.43cvss 6.5epss 0.04

    Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.

  • CVE-2016-1159MedMar 9, 2020
    risk 0.43cvss 6.5epss 0.04

    In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.

  • CVE-2019-12543MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the PurchaseRequest.do serviceRequestId parameter.

  • CVE-2019-12542MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.

Page 5 of 9