Vendor CVEs
Zohocorp
All CVEs
562 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37919 | Cri | 0.65 | 9.8 | 0.11 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37925 | Cri | 0.65 | 9.8 | 0.10 | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. | ||
| CVE-2021-33055 | Cri | 0.65 | 9.8 | 0.18 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. | ||
| CVE-2021-28959 | Cri | 0.65 | 9.8 | 0.17 | Apr 30, 2021 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. | ||
| CVE-2018-5353 | Cri | 0.65 | 9.8 | 0.11 | Sep 30, 2020 | The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable… | ||
| CVE-2020-24786 | Cri | 0.65 | 9.8 | 0.13 | Aug 31, 2020 | An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer… | ||
| CVE-2020-15588 | Cri | 0.65 | 9.8 | 0.13 | Jul 29, 2020 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code… | ||
| CVE-2020-11518 | Cri | 0.65 | 9.8 | 0.19 | Apr 4, 2020 | Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. | ||
| CVE-2020-10541 | Cri | 0.65 | 9.8 | 0.10 | Mar 13, 2020 | Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108. | ||
| CVE-2020-8540 | Cri | 0.65 | 9.8 | 0.13 | Mar 11, 2020 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. | ||
| CVE-2019-3905 | Cri | 0.65 | 10.0 | 0.03 | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. | ||
| CVE-2018-20338 | Cri | 0.65 | 9.8 | 0.12 | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section. | ||
| CVE-2018-18475 | Cri | 0.65 | 9.8 | 0.20 | Oct 23, 2018 | Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. | ||
| CVE-2018-11716 | Cri | 0.65 | 9.8 | 0.14 | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords,… | ||
| CVE-2016-9498 | Cri | 0.65 | 9.8 | 0.22 | Jul 13, 2018 | ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating… | ||
| CVE-2017-16851 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. | ||
| CVE-2017-16850 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. | ||
| CVE-2017-16849 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter. | ||
| CVE-2017-16848 | Cri | 0.65 | 9.8 | 0.15 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter. | ||
| CVE-2017-16847 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action. | ||
| CVE-2017-16846 | Cri | 0.65 | 9.8 | 0.17 | Nov 16, 2017 | Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter. | ||
| CVE-2015-2560 | Cri | 0.65 | 9.8 | 0.16 | Aug 2, 2017 | Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet. | ||
| CVE-2025-8324 | Cri | 0.64 | 9.8 | 0.02 | Nov 11, 2025 | Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration. | ||
| CVE-2023-48793 | Cri | 0.64 | 9.8 | 0.07 | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature. | ||
| CVE-2023-48792 | Cri | 0.64 | 9.8 | 0.07 | Feb 2, 2024 | Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option. | ||
| CVE-2023-35854 | Cri | 0.64 | 9.8 | 0.06 | Jun 20, 2023 | Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is… | ||
| CVE-2023-31099 | Hig | 0.64 | 8.8 | 0.82 | May 4, 2023 | Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers. | ||
| CVE-2020-21642 | Cri | 0.64 | 9.8 | 0.07 | Aug 15, 2022 | Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code. | ||
| CVE-2022-36412 | Cri | 0.64 | 9.8 | 0.05 | Jul 26, 2022 | In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.) | ||
| CVE-2022-24306 | Cri | 0.64 | 9.8 | 0.02 | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. | ||
| CVE-2022-24305 | Cri | 0.64 | 9.8 | 0.03 | Mar 2, 2022 | Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. | ||
| CVE-2021-44526 | Cri | 0.64 | 9.8 | 0.03 | Dec 23, 2021 | Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. | ||
| CVE-2021-44525 | Cri | 0.64 | 9.8 | 0.03 | Dec 20, 2021 | Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required. | ||
| CVE-2021-44676 | Cri | 0.64 | 9.8 | 0.04 | Dec 20, 2021 | Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state. | ||
| CVE-2021-44675 | Cri | 0.64 | 9.8 | 0.06 | Dec 20, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required. | ||
| CVE-2021-44514 | Cri | 0.64 | 9.8 | 0.05 | Dec 9, 2021 | OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. | ||
| CVE-2021-42099 | Cri | 0.64 | 9.8 | 0.07 | Nov 30, 2021 | Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. | ||
| CVE-2021-42002 | Cri | 0.64 | 9.8 | 0.07 | Nov 11, 2021 | Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution. | ||
| CVE-2021-41833 | Cri | 0.64 | 9.8 | 0.08 | Nov 11, 2021 | Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. | ||
| CVE-2021-41080 | Cri | 0.64 | 9.8 | 0.04 | Nov 11, 2021 | Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search. | ||
| CVE-2020-24743 | Cri | 0.64 | 9.8 | 0.03 | Nov 3, 2021 | An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter. | ||
| CVE-2021-41075 | Cri | 0.64 | 9.8 | 0.03 | Oct 13, 2021 | The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API. | ||
| CVE-2021-38298 | Cri | 0.64 | 9.8 | 0.03 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. | ||
| CVE-2021-37931 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37930 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37929 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37928 | Cri | 0.64 | 9.8 | 0.10 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution. | ||
| CVE-2021-37762 | Cri | 0.64 | 9.8 | 0.08 | Oct 7, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. | ||
| CVE-2021-37761 | Cri | 0.64 | 9.8 | 0.10 | Sep 27, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. | ||
| CVE-2021-37927 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. |
- risk 0.65cvss 9.8epss 0.11
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.65cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
- risk 0.65cvss 9.8epss 0.18
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.
- risk 0.65cvss 9.8epss 0.11
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable…
- risk 0.65cvss 9.8epss 0.13
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033, RecoverManager Plus before build number 6017, EventLog Analyzer…
- risk 0.65cvss 9.8epss 0.13
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code…
- risk 0.65cvss 9.8epss 0.19
Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution.
- risk 0.65cvss 9.8epss 0.10
Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.
- risk 0.65cvss 9.8epss 0.13
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
- risk 0.65cvss 10.0epss 0.03
Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.
- risk 0.65cvss 9.8epss 0.12
Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.
- risk 0.65cvss 9.8epss 0.20
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.
- risk 0.65cvss 9.8epss 0.14
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (private information such as location of enrolled devices, cleartext passwords,…
- risk 0.65cvss 9.8epss 0.22
ManageEngine Applications Manager 12 and 13 before build 13200, allows unserialization of unsafe Java objects. The vulnerability can be exploited by remote user without authentication and it allows to execute remote code compromising the application as well as the operating…
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do?method=viewDashBoard forpage parameter.
- risk 0.65cvss 9.8epss 0.15
Zoho ManageEngine Applications Manager 13 allows SQL injection via the /manageConfMons.do groupname parameter.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.
- risk 0.65cvss 9.8epss 0.16
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
- risk 0.64cvss 9.8epss 0.02
Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the improper filter configuration.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
- risk 0.64cvss 9.8epss 0.06
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is…
- risk 0.64cvss 8.8epss 0.82
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
- risk 0.64cvss 9.8epss 0.07
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
- risk 0.64cvss 9.8epss 0.05
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
- risk 0.64cvss 9.8epss 0.06
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
- risk 0.64cvss 9.8epss 0.05
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution.
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search.
- risk 0.64cvss 9.8epss 0.03
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
- risk 0.64cvss 9.8epss 0.03
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
Page 2 of 12