VYPR

Vendor CVEs

Zohocorp

All CVEs

568 total · sorted by risk
  • CVE-2021-37927CriSep 22, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

  • CVE-2021-37424CriSep 21, 2021
    risk 0.64cvss 9.8epss 0.05

    ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.

  • CVE-2021-37422CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.

  • CVE-2021-37423CriSep 10, 2021
    risk 0.64cvss 9.8epss 0.03

    Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.

  • CVE-2021-37421CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.

  • CVE-2021-37417CriAug 30, 2021
    risk 0.64cvss 9.8epss 0.05

    Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.

  • CVE-2021-40177CriAug 29, 2021
    risk 0.64cvss 9.8epss 0.05

    Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.

  • CVE-2021-40175CriAug 29, 2021
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.

  • CVE-2021-33256HigAug 9, 2021
    risk 0.64cvss 8.8epss 0.79

    A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User…

  • CVE-2021-20110CriJul 19, 2021
    risk 0.64cvss 9.8epss 0.07

    Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on…

  • CVE-2021-33911CriJul 17, 2021
    risk 0.64cvss 9.8epss 0.05

    Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.

  • CVE-2021-31531CriJun 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).

  • CVE-2021-20078CriApr 1, 2021
    risk 0.64cvss 9.1epss 0.60

    Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

  • CVE-2020-29658CriMar 5, 2021
    risk 0.64cvss 9.8epss 0.04

    Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.

  • CVE-2020-27995CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.09

    SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.

  • CVE-2020-15533CriOct 1, 2020
    risk 0.64cvss 9.8epss 0.04

    In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.

  • CVE-2020-15394CriSep 25, 2020
    risk 0.64cvss 9.8epss 0.08

    The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.

  • CVE-2020-11552CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.07

    An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a…

  • CVE-2020-9347CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.08

    Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be…

  • CVE-2019-19649CriDec 11, 2019
    risk 0.64cvss 9.8epss 0.10

    Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.

  • CVE-2019-11678CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.

  • CVE-2019-11677CriMay 2, 2019
    risk 0.64cvss 9.8epss 0.09

    The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.

  • CVE-2019-8395CriFeb 17, 2019
    risk 0.64cvss 9.8epss 0.06

    An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.

  • CVE-2018-20664CriJan 3, 2019
    risk 0.64cvss 9.8epss 0.07

    Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

  • CVE-2018-15168CriAug 8, 2018
    risk 0.64cvss 9.8epss 0.04

    A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.

  • CVE-2018-11717CriJul 16, 2018
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and…

  • CVE-2018-10466CriMay 29, 2018
    risk 0.64cvss 9.8epss 0.16

    Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.

  • CVE-2018-5341CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.

  • CVE-2018-5339CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.07

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.

  • CVE-2018-5338CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.

  • CVE-2018-5337CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.

  • CVE-2017-16924CriFeb 19, 2018
    risk 0.64cvss 9.8epss 0.08

    Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL,…

  • CVE-2015-9107CriAug 4, 2017
    risk 0.64cvss 9.8epss 0.04

    Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.

  • CVE-2025-3835CriJun 9, 2025
    risk 0.63cvss 9.6epss 0.02

    Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

  • CVE-2023-47211CriJan 8, 2024
    risk 0.63cvss 9.1epss 0.47

    A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.

  • CVE-2022-38772HigAug 29, 2022
    risk 0.63cvss 8.8epss 0.78

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.

  • CVE-2022-37024HigAug 10, 2022
    risk 0.63cvss 8.8epss 0.79

    Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code…

  • CVE-2019-10008HigApr 24, 2019
    risk 0.62cvss 8.8epss 0.22

    Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect…

  • CVE-2019-8394MedKEVFeb 17, 2019
    risk 0.62cvss 6.5epss 0.63

    Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.

  • CVE-2024-24409HigNov 8, 2024
    risk 0.61cvss 8.8epss 0.06

    Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

  • CVE-2022-29457HigApr 18, 2022
    risk 0.61cvss 8.8epss 0.08

    Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.

  • CVE-2021-44757CriJan 18, 2022
    risk 0.61cvss 9.1epss 0.24

    Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.

  • CVE-2020-16267HigOct 6, 2020
    risk 0.61cvss 8.8epss 0.43

    Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.

  • CVE-2019-19774HigDec 13, 2019
    risk 0.61cvss 8.8epss 0.13

    An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing…

  • CVE-2019-15105HigAug 16, 2019
    risk 0.61cvss 8.8epss 0.08

    An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can…

  • CVE-2019-15104HigAug 16, 2019
    risk 0.61cvss 8.8epss 0.08

    An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently…

  • CVE-2017-16542HigNov 5, 2017
    risk 0.61cvss 8.8epss 0.05

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

  • CVE-2022-27908HigApr 18, 2022
    risk 0.60cvss 8.8epss 0.36

    Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.

  • CVE-2021-20130HigOct 13, 2021
    risk 0.60cvss 8.8epss 0.33

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.

  • CVE-2020-28050CriMar 5, 2021
    risk 0.60cvss 9.1epss 0.05

    Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.

Page 3 of 12