Zohocorp
Products
71- 66 CVEs
- 60 CVEs
- 57 CVEs
- 54 CVEs
- 52 CVEs
- 52 CVEs
- 50 CVEs
- 31 CVEs
- 29 CVEs
- 28 CVEs
- 27 CVEs
- 26 CVEs
- 24 CVEs
- 19 CVEs
- 15 CVEs
- 15 CVEs
- 14 CVEs
- 13 CVEs
- 11 CVEs
- 10 CVEs
- 10 CVEs
- 8 CVEs
- 8 CVEs
- 7 CVEs
- 6 CVEs
- 6 CVEs
- 6 CVEs
- 6 CVEs
- 5 CVEs
- 5 CVEs
- View all 71 products →
Recent CVEs
562| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-47966 | Cri | 0.93 | 9.8 | 1.00 | KEV | Jan 18, 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application… | |
| CVE-2021-40539 | Cri | 0.93 | 9.8 | 0.99 | KEV | Sep 7, 2021 | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | |
| CVE-2022-35405 | Cri | 0.87 | 9.8 | 1.00 | KEV | Jul 19, 2022 | Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) | |
| CVE-2020-10189 | Cri | 0.87 | 9.8 | 1.00 | KEV | Mar 6, 2020 | Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets. | |
| CVE-2021-44077 | Cri | 0.86 | 9.8 | 0.93 | KEV | Nov 29, 2021 | Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration. | |
| CVE-2021-44515 | Cri | 0.84 | 9.8 | 1.00 | KEV | Dec 12, 2021 | Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through… | |
| CVE-2021-37415 | Cri | 0.84 | 9.8 | 1.00 | KEV | Sep 1, 2021 | Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | |
| CVE-2022-28219 | Cri | 0.74 | 9.8 | 0.97 | Apr 5, 2022 | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | ||
| CVE-2016-6603 | Cri | 0.74 | 9.8 | 0.87 | Jan 23, 2017 | ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header. | ||
| CVE-2016-6600 | Cri | 0.74 | 9.8 | 0.91 | Jan 23, 2017 | Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet. | ||
| CVE-2020-28653 | Cri | 0.73 | 9.8 | 0.79 | Feb 3, 2021 | Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet. | ||
| CVE-2020-11532 | Cri | 0.73 | 9.8 | 0.77 | May 8, 2020 | Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user. | ||
| CVE-2013-7390 | Cri | 0.73 | 9.8 | 0.75 | Jan 27, 2020 | Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the… | ||
| CVE-2014-7862 | Cri | 0.73 | 9.8 | 0.81 | Jan 4, 2018 | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action. | ||
| CVE-2022-40300 | Cri | 0.72 | 9.8 | 0.99 | Sep 16, 2022 | Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities. | ||
| CVE-2021-42847 | Cri | 0.72 | 9.8 | 0.70 | Nov 11, 2021 | Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. | ||
| CVE-2022-29535 | Cri | 0.71 | 9.8 | 0.92 | May 5, 2022 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. | ||
| CVE-2021-37539 | Cri | 0.71 | 9.8 | 0.93 | Sep 27, 2021 | Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. | ||
| CVE-2021-3287 | Cri | 0.71 | 9.8 | 0.51 | Apr 22, 2021 | Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. | ||
| CVE-2016-6602 | Cri | 0.71 | 9.8 | 0.55 | Jan 23, 2017 | ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a… |
- risk 0.93cvss 9.8epss 1.00
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application…
- risk 0.93cvss 9.8epss 0.99
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
- risk 0.87cvss 9.8epss 1.00
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
- risk 0.87cvss 9.8epss 1.00
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
- risk 0.86cvss 9.8epss 0.93
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.
- risk 0.84cvss 9.8epss 1.00
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through…
- risk 0.84cvss 9.8epss 1.00
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
- risk 0.74cvss 9.8epss 0.97
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
- risk 0.74cvss 9.8epss 0.87
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.
- risk 0.74cvss 9.8epss 0.91
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.
- risk 0.73cvss 9.8epss 0.79
Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.
- risk 0.73cvss 9.8epss 0.77
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.
- risk 0.73cvss 9.8epss 0.75
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…
- risk 0.73cvss 9.8epss 0.81
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
- risk 0.72cvss 9.8epss 0.99
Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.
- risk 0.72cvss 9.8epss 0.70
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
- risk 0.71cvss 9.8epss 0.92
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
- risk 0.71cvss 9.8epss 0.93
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
- risk 0.71cvss 9.8epss 0.51
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
- risk 0.71cvss 9.8epss 0.55
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a…