VYPR

Vendor CVEs

Zohocorp

All CVEs

562 total · sorted by risk
  • CVE-2021-31159MedJun 16, 2021
    risk 0.39cvss 5.3epss 0.18

    Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

  • CVE-2017-14582MedSep 30, 2017
    risk 0.39cvss 5.9epss 0.02

    The Zoho Site24x7 Mobile Network Poller application before 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a self-signed certificate.

  • CVE-2018-9163MedApr 2, 2018
    risk 0.38cvss 5.4epss 0.05

    A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.

  • CVE-2025-9435MedJan 13, 2026
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

  • CVE-2024-27311MedJul 17, 2024
    risk 0.36cvss 5.5epss 0.01

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.

  • CVE-2024-36037MedMay 27, 2024
    risk 0.36cvss 5.5epss 0.00

    Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

  • CVE-2023-6105MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.01

    An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt…

  • CVE-2022-23779MedMar 2, 2022
    risk 0.36cvss 5.3epss 0.15

    Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.

  • CVE-2024-27310MedMay 27, 2024
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

  • CVE-2023-49943MedJan 18, 2024
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

  • CVE-2023-41904MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.

  • CVE-2023-38331MedJul 28, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.

  • CVE-2023-37308MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.

  • CVE-2023-34197MedJul 7, 2023
    risk 0.35cvss 5.4epss 0.04

    Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make…

  • CVE-2023-0169MedFeb 13, 2023
    risk 0.35cvss 5.4epss 0.02

    The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…

  • CVE-2022-28987MedMay 20, 2022
    risk 0.35cvss 5.3epss 0.10

    Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.

  • CVE-2022-26777MedApr 16, 2022
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.

  • CVE-2022-26653MedApr 16, 2022
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).

  • CVE-2022-25373MedApr 5, 2022
    risk 0.35cvss 5.4epss 0.01

    Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.

  • CVE-2022-25245MedApr 5, 2022
    risk 0.35cvss 5.3epss 0.01

    Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.

  • CVE-2021-20147MedJan 3, 2022
    risk 0.35cvss 5.3epss 0.07

    ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.

  • CVE-2021-37922MedOct 7, 2021
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

  • CVE-2021-33849MedOct 5, 2021
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's…

  • CVE-2021-33617MedJul 31, 2021
    risk 0.35cvss 5.3epss 0.02

    Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

  • CVE-2021-28382MedJun 7, 2021
    risk 0.35cvss 5.4epss 0.01

    Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.

  • CVE-2019-16962MedJan 6, 2021
    risk 0.35cvss 5.4epss 0.02

    Zoho ManageEngine Desktop Central 10.0.430 allows HTML injection via a modified Report Name in a New Custom Report.

  • CVE-2019-19799MedMar 13, 2020
    risk 0.35cvss 5.3epss 0.06

    Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet.

  • CVE-2019-19800MedFeb 6, 2020
    risk 0.35cvss 5.3epss 0.04

    Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.

  • CVE-2019-15045MedAug 21, 2019
    risk 0.35cvss 5.3epss 0.05

    AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality

  • CVE-2017-11560MedMay 23, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. By adding a Google Map to the application, an authenticated user can upload an HTML file. This HTML file is then rendered in various locations of the application. JavaScript inside the uploaded HTML is also interpreted…

  • CVE-2017-11557MedMay 23, 2019
    risk 0.35cvss 5.3epss 0.04

    An issue was discovered in ZOHO ManageEngine Applications Manager 12.3. It is possible for an unauthenticated user to view the list of domain names and usernames used in a company's network environment via a userconfiguration.do?method=editUser request.

  • CVE-2018-7248MedMay 11, 2018
    risk 0.35cvss 5.3epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists,…

  • CVE-2016-4890MedApr 14, 2017
    risk 0.35cvss 5.3epss 0.03

    ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.

  • CVE-2016-4888MedApr 14, 2017
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ServiceDesk Plus before 9.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2025-7473MedOct 21, 2025
    risk 0.34cvss 5.2epss 0.00

    Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

  • CVE-2023-39912MedAug 31, 2023
    risk 0.32cvss 4.9epss 0.04

    Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.

  • CVE-2023-35786MedJul 5, 2023
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.

  • CVE-2023-29443MedApr 26, 2023
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.

  • CVE-2022-40771MedNov 23, 2022
    risk 0.32cvss 4.9epss 0.03

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure.

  • CVE-2019-8925MedMay 17, 2019
    risk 0.32cvss 4.3epss 0.12

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePath), allows remote authenticated users to bypass intended…

  • CVE-2019-10273MedApr 4, 2019
    risk 0.32cvss 4.3epss 0.08

    Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

  • CVE-2016-9491MedJul 13, 2018
    risk 0.32cvss 4.9epss 0.03

    ManageEngine Applications Manager 12 and 13 before build 13690 allows an authenticated user, who is able to access /register.do page (most likely limited to administrator), to browse the filesystem and read the system files, including Applications Manager configuration, stored…

  • CVE-2024-5678MedAug 1, 2024
    risk 0.31cvss 4.7epss 0.03

    Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL Injection in the Create Monitor feature.

  • CVE-2024-21791MedMay 22, 2024
    risk 0.31cvss 4.7epss 0.02

    Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.

  • CVE-2019-16268MedFeb 3, 2021
    risk 0.31cvss 4.8epss 0.02

    Zoho ManageEngine Remote Access Plus 10.0.259 allows HTML injection via the Description field on the Admin - User Administration userMgmt.do?actionToCall=ShowUser screen.

  • CVE-2020-6843MedJan 23, 2020
    risk 0.31cvss 4.8epss 0.02

    Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.

  • CVE-2025-5342MedOct 30, 2025
    risk 0.28cvss 4.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

  • CVE-2025-41437MedJun 9, 2025
    risk 0.28cvss 4.3epss 0.00

    Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.

  • CVE-2023-29505MedAug 4, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.

  • CVE-2022-24446MedMar 1, 2022
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.

Page 10 of 12