VYPR

Vendor CVEs

Zoho

All CVEs

422 total · sorted by risk
  • CVE-2019-12597MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.

  • CVE-2019-12596MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.

  • CVE-2019-12595MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.

  • CVE-2019-12540MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.

  • CVE-2019-12539MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.03

    An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.

  • CVE-2019-12537MedJul 11, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.

  • CVE-2019-5962MedJul 5, 2019
    risk 0.40cvss 6.1epss 0.02

    Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2019-8346MedMay 24, 2019
    risk 0.40cvss 6.1epss 0.04

    In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD…

  • CVE-2017-11739MedMay 23, 2019
    risk 0.40cvss 6.1epss 0.03

    In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be…

  • CVE-2019-7427MedMay 7, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.

  • CVE-2019-7426MedMay 7, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.

  • CVE-2019-11676MedMay 2, 2019
    risk 0.40cvss 6.1epss 0.02

    The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.

  • CVE-2019-11511MedApr 25, 2019
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.

  • CVE-2019-7425MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.

  • CVE-2019-7424MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is…

  • CVE-2019-7423MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.

  • CVE-2019-7422MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.

  • CVE-2018-20339MedDec 21, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.

  • CVE-2018-19921MedDec 6, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.

  • CVE-2018-18716MedNov 20, 2018
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.

  • CVE-2018-18715MedNov 20, 2018
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.

  • CVE-2018-19288MedNov 15, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.

  • CVE-2018-18262MedOct 17, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.

  • CVE-2018-17596MedOct 2, 2018
    risk 0.40cvss 6.1epss 0.02

    In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.

  • CVE-2018-16965MedSep 21, 2018
    risk 0.40cvss 6.1epss 0.03

    In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.

  • CVE-2018-10075MedJul 2, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.

  • CVE-2018-10803MedMay 10, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through…

  • CVE-2018-5799MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.02

    In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.

  • CVE-2018-8722MedMar 15, 2018
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.

  • CVE-2017-17698MedDec 15, 2017
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.

  • CVE-2017-11687MedJul 27, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.

  • CVE-2017-11686MedJul 27, 2017
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.

  • CVE-2017-11685MedJul 27, 2017
    risk 0.40cvss 6.1epss 0.01

    Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.

  • CVE-2021-46065MedJan 27, 2022
    risk 0.39cvss 4.8epss 0.92

    A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.

  • CVE-2021-31874MedJul 2, 2021
    risk 0.39cvss 5.9epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application.

  • CVE-2021-31857MedJun 16, 2021
    risk 0.39cvss 5.9epss 0.03

    In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.

  • CVE-2021-31159MedJun 16, 2021
    risk 0.39cvss 5.3epss 0.18

    Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

  • CVE-2017-14582MedSep 30, 2017
    risk 0.39cvss 5.9epss 0.02

    The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.

  • CVE-2018-9163MedApr 2, 2018
    risk 0.38cvss 5.4epss 0.05

    A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.

  • CVE-2024-36037MedMay 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

  • CVE-2022-23779MedMar 2, 2022
    risk 0.36cvss 5.3epss 0.15

    Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

  • CVE-2026-24595MedJan 23, 2026
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in zohocrm Zoho CRM Lead Magnet zoho-crm-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho CRM Lead Magnet: from n/a through <= 1.8.1.9.

  • CVE-2024-27310MedMay 27, 2024
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

  • CVE-2023-49943MedJan 18, 2024
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

  • CVE-2023-41904MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.

  • CVE-2023-38331MedJul 28, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

  • CVE-2023-37308MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.

  • CVE-2023-34197MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.04

    Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make…

  • CVE-2022-28987MedMay 20, 2022
    risk 0.35cvss 5.3epss 0.10

    Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.

  • CVE-2022-26777MedApr 16, 2022
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

Page 7 of 9