VYPR

Vendor CVEs

Zohocorp

All CVEs

562 total · sorted by risk
  • CVE-2022-47966CriKEVJan 18, 2023
    risk 0.93cvss 9.8epss 1.00

    Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application…

  • CVE-2021-40539CriKEVSep 7, 2021
    risk 0.93cvss 9.8epss 0.99

    Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.

  • CVE-2022-35405CriKEVJul 19, 2022
    risk 0.87cvss 9.8epss 1.00

    Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

  • CVE-2020-10189CriKEVMar 6, 2020
    risk 0.87cvss 9.8epss 1.00

    Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.

  • CVE-2021-44077CriKEVNov 29, 2021
    risk 0.86cvss 9.8epss 0.93

    Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

  • CVE-2021-44515CriKEVDec 12, 2021
    risk 0.84cvss 9.8epss 1.00

    Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through…

  • CVE-2021-37415CriKEVSep 1, 2021
    risk 0.84cvss 9.8epss 1.00

    Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

  • CVE-2022-28219CriApr 5, 2022
    risk 0.74cvss 9.8epss 0.97

    Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

  • CVE-2016-6603CriJan 23, 2017
    risk 0.74cvss 9.8epss 0.87

    ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

  • CVE-2016-6600CriJan 23, 2017
    risk 0.74cvss 9.8epss 0.91

    Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

  • CVE-2020-28653CriFeb 3, 2021
    risk 0.73cvss 9.8epss 0.79

    Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

  • CVE-2020-11532CriMay 8, 2020
    risk 0.73cvss 9.8epss 0.77

    Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations in the context of admin user.

  • CVE-2013-7390CriJan 27, 2020
    risk 0.73cvss 9.8epss 0.75

    Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the…

  • CVE-2014-7862CriJan 4, 2018
    risk 0.73cvss 9.8epss 0.81

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

  • CVE-2022-40300CriSep 16, 2022
    risk 0.72cvss 9.8epss 0.99

    Zoho ManageEngine Password Manager Pro through 12120 before 12121, PAM360 through 5550 before 5600, and Access Manager Plus through 4304 before 4305 have multiple SQL injection vulnerabilities.

  • CVE-2021-42847CriNov 11, 2021
    risk 0.72cvss 9.8epss 0.70

    Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.

  • CVE-2022-29535CriMay 5, 2022
    risk 0.71cvss 9.8epss 0.92

    Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

  • CVE-2021-37539CriSep 27, 2021
    risk 0.71cvss 9.8epss 0.93

    Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.

  • CVE-2021-3287CriApr 22, 2021
    risk 0.71cvss 9.8epss 0.51

    Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

  • CVE-2016-6602CriJan 23, 2017
    risk 0.71cvss 9.8epss 0.55

    ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a…

  • CVE-2023-23076CriFeb 1, 2023
    risk 0.70cvss 9.8epss 0.74

    OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.

  • CVE-2022-43671CriNov 12, 2022
    risk 0.70cvss 9.8epss 0.75

    Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection.

  • CVE-2022-29081CriApr 28, 2022
    risk 0.70cvss 9.8epss 0.84

    Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via…

  • CVE-2021-37926CriOct 7, 2021
    risk 0.70cvss 9.8epss 0.74

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37918CriOct 7, 2021
    risk 0.70cvss 9.8epss 0.74

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-41288CriSep 30, 2021
    risk 0.70cvss 9.8epss 0.80

    Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

  • CVE-2021-28958CriJun 25, 2021
    risk 0.70cvss 9.8epss 0.73

    Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

  • CVE-2014-5007CriJan 17, 2020
    risk 0.70cvss 9.8epss 0.37

    Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot…

  • CVE-2019-17602CriOct 15, 2019
    risk 0.70cvss 9.8epss 0.82

    An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.

  • CVE-2018-17243CriSep 20, 2018
    risk 0.70cvss 9.8epss 0.74

    Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.

  • CVE-2017-11346CriJul 17, 2017
    risk 0.70cvss 9.8epss 0.43

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

  • CVE-2022-47523CriJan 5, 2023
    risk 0.69cvss 9.8epss 0.71

    Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.

  • CVE-2022-43672CriNov 12, 2022
    risk 0.69cvss 9.8epss 0.67

    Zoho ManageEngine Password Manager Pro before 12122, PAM360 before 5711, and Access Manager Plus before 4306 allow SQL Injection (in a different software component relative to CVE-2022-43671.

  • CVE-2021-41081CriNov 11, 2021
    risk 0.69cvss 9.8epss 0.63

    Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search.

  • CVE-2019-15106CriAug 16, 2019
    risk 0.69cvss 9.8epss 0.25

    An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.

  • CVE-2019-12196CriJun 5, 2019
    risk 0.69cvss 9.8epss 0.69

    A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.

  • CVE-2021-40493CriOct 13, 2021
    risk 0.68cvss 9.8epss 0.50

    Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.

  • CVE-2019-11469CriApr 23, 2019
    risk 0.68cvss 9.8epss 0.18

    Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious file via the "Execute Program Action(s)" feature.

  • CVE-2019-11448CriApr 22, 2019
    risk 0.68cvss 9.8epss 0.12

    An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For example, the attacker can subsequently write arbitrary text to…

  • CVE-2018-13050CriJul 2, 2018
    risk 0.67cvss 9.8epss 0.40

    A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.

  • CVE-2017-16543CriNov 5, 2017
    risk 0.67cvss 9.8epss 0.06

    Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

  • CVE-2018-20173CriDec 17, 2018
    risk 0.66cvss 9.8epss 0.24

    Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.

  • CVE-2018-18949CriNov 5, 2018
    risk 0.66cvss 9.8epss 0.24

    Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.

  • CVE-2017-7213CriMay 15, 2017
    risk 0.66cvss 10.0epss 0.08

    Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

  • CVE-2021-43319CriNov 30, 2021
    risk 0.65cvss 9.8epss 0.21

    Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.

  • CVE-2021-20136CriNov 1, 2021
    risk 0.65cvss 9.8epss 0.10

    ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled…

  • CVE-2021-37924CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37923CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37921CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

  • CVE-2021-37920CriOct 7, 2021
    risk 0.65cvss 9.8epss 0.11

    Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

Page 1 of 12