VYPR

Vendor CVEs

Zoho

All CVEs

422 total · sorted by risk
  • CVE-2022-26653MedApr 16, 2022
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).

  • CVE-2022-25373MedApr 5, 2022
    risk 0.35cvss 5.4epss 0.01

    Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

  • CVE-2022-25245MedApr 5, 2022
    risk 0.35cvss 5.3epss 0.01

    Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

  • CVE-2021-37922MedOct 7, 2021
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

  • CVE-2021-33849MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's…

  • CVE-2021-33617MedJul 31, 2021
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

  • CVE-2021-28382MedJun 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

  • CVE-2019-16962MedJan 6, 2021
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.

  • CVE-2019-19799MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.06

    Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

  • CVE-2019-19800MedFeb 6, 2020
    risk 0.35cvss 5.3epss 0.04

    Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

  • CVE-2019-19306MedNov 26, 2019
    risk 0.35cvss 5.4epss 0.01

    The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.

  • CVE-2019-15045MedAug 21, 2019
    risk 0.35cvss 5.3epss 0.05

    AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality

  • CVE-2017-11560MedMay 23, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted…

  • CVE-2017-11557MedMay 23, 2019
    risk 0.35cvss 5.3epss 0.04

    An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.

  • CVE-2018-7248MedMay 11, 2018
    risk 0.35cvss 5.3epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists,…

  • CVE-2016-4890MedApr 14, 2017
    risk 0.35cvss 5.3epss 0.03

    ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.

  • CVE-2016-4888MedApr 14, 2017
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2023-39912MedAug 31, 2023
    risk 0.32cvss 4.9epss 0.04

    Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.

  • CVE-2023-35786MedJul 5, 2023
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

  • CVE-2023-29443MedApr 26, 2023
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

  • CVE-2022-40771MedNov 23, 2022
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.

  • CVE-2019-8925MedMay 17, 2019
    risk 0.32cvss 4.3epss 0.12

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended…

  • CVE-2024-21791MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

  • CVE-2019-16268MedFeb 3, 2021
    risk 0.31cvss 4.8epss 0.02

    Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.

  • CVE-2020-6843MedJan 23, 2020
    risk 0.31cvss 4.8epss 0.02

    Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.

  • CVE-2025-67972MedFeb 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Zoho Mail Zoho ZeptoMail allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Zoho ZeptoMail: from n/a through 3.2.9.

  • CVE-2025-59568MedSep 22, 2025
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Zoho Flow Zoho Flow zoho-flow allows Cross Site Request Forgery.This issue affects Zoho Flow: from n/a through <= 2.14.1.

  • CVE-2025-31408MedApr 1, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Zoho Flow Zoho Flow zoho-flow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zoho Flow: from n/a through <= 2.13.3.

  • CVE-2024-32442MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7.

  • CVE-2024-32441MedApr 15, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Zoho Campaigns.This issue affects Zoho Campaigns: from n/a through 2.0.7.

  • CVE-2023-29505MedAug 4, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

  • CVE-2022-24446MedMar 1, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.

  • CVE-2020-15595MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Zoho Application Control Plus before version 10.0.511. The Element Configuration feature (to configure elements included in the scope of elements managed by the product) allows an attacker to retrieve the entire list of the IP ranges and subnets…

  • CVE-2020-15594MedSep 30, 2020
    risk 0.28cvss 4.3epss 0.02

    An SSRF issue was discovered in Zoho Application Control Plus before version 10.0.511. The mail gateway configuration feature allows an attacker to perform a scan in order to discover open ports on a machine as well as available machines on the network segment on which the…

  • CVE-2019-20474MedFeb 17, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network…

  • CVE-2020-8422MedJan 31, 2020
    risk 0.28cvss 4.3epss 0.01

    An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name,…

  • CVE-2019-17112MedOct 9, 2019
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).

  • CVE-2024-36036MedMay 27, 2024
    risk 0.27cvss 4.2epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

  • CVE-2022-42903LowNov 17, 2022
    risk 0.21cvss 3.3epss 0.00

    Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list.

  • CVE-2022-28810MedKEVApr 18, 2022
    risk 0.21cvss 6.8epss 0.71

    Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this…

  • CVE-2023-50785LowJan 25, 2024
    risk 0.18cvss 2.7epss 0.02

    Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.

  • CVE-2024-27314LowMay 27, 2024
    risk 0.16cvss 2.4epss 0.02

    Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.

  • CVE-2015-7766Oct 9, 2015
    risk 0.09cvss epss 0.81

    PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comment in the query to api/json/admin/SubmitQuery, as demonstrated by "INSERT/**/INTO."

  • CVE-2014-7866Dec 10, 2014
    risk 0.09cvss epss 0.80

    Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName…

  • CVE-2014-7868Dec 4, 2014
    risk 0.09cvss epss 0.73

    Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a Delete operation to the…

  • CVE-2014-6034Dec 4, 2014
    risk 0.09cvss epss 0.79

    Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote authenticated users to write to…

  • CVE-2014-5005Oct 21, 2014
    risk 0.09cvss epss 0.78

    Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.

  • CVE-2015-7765Oct 9, 2015
    risk 0.08cvss epss 0.67

    ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allows remote authenticated users to obtain administrator access by leveraging knowledge of this password.

  • CVE-2014-5446Dec 4, 2014
    risk 0.07cvss epss 0.55

    Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

  • CVE-2014-6036Dec 4, 2014
    risk 0.06cvss epss 0.36

    Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the…

Page 8 of 9