Vendor CVEs
Zohocorp
All CVEs
568 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-37927 | Cri | 0.64 | 9.8 | 0.02 | Sep 22, 2021 | Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. | ||
| CVE-2021-37424 | Cri | 0.64 | 9.8 | 0.05 | Sep 21, 2021 | ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. | ||
| CVE-2021-37422 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. | ||
| CVE-2021-37423 | Cri | 0.64 | 9.8 | 0.03 | Sep 10, 2021 | Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. | ||
| CVE-2021-37421 | Cri | 0.64 | 9.8 | 0.02 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. | ||
| CVE-2021-37417 | Cri | 0.64 | 9.8 | 0.05 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. | ||
| CVE-2021-40177 | Cri | 0.64 | 9.8 | 0.05 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. | ||
| CVE-2021-40175 | Cri | 0.64 | 9.8 | 0.07 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. | ||
| CVE-2021-33256 | Hig | 0.64 | 8.8 | 0.79 | Aug 9, 2021 | A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User… | ||
| CVE-2021-20110 | Cri | 0.64 | 9.8 | 0.07 | Jul 19, 2021 | Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on… | ||
| CVE-2021-33911 | Cri | 0.64 | 9.8 | 0.05 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. | ||
| CVE-2021-31531 | Cri | 0.64 | 9.8 | 0.02 | Jun 29, 2021 | Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). | ||
| CVE-2021-20078 | Cri | 0.64 | 9.1 | 0.60 | Apr 1, 2021 | Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS. | ||
| CVE-2020-29658 | Cri | 0.64 | 9.8 | 0.04 | Mar 5, 2021 | Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation. | ||
| CVE-2020-27995 | Cri | 0.64 | 9.8 | 0.09 | Oct 29, 2020 | SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter. | ||
| CVE-2020-15533 | Cri | 0.64 | 9.8 | 0.04 | Oct 1, 2020 | In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack. | ||
| CVE-2020-15394 | Cri | 0.64 | 9.8 | 0.08 | Sep 25, 2020 | The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution. | ||
| CVE-2020-11552 | Cri | 0.64 | 9.8 | 0.07 | Aug 11, 2020 | An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a… | ||
| CVE-2020-9347 | Cri | 0.64 | 9.8 | 0.08 | Mar 16, 2020 | Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be… | ||
| CVE-2019-19649 | Cri | 0.64 | 9.8 | 0.10 | Dec 11, 2019 | Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function. | ||
| CVE-2019-11678 | Cri | 0.64 | 9.8 | 0.09 | May 2, 2019 | The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection. | ||
| CVE-2019-11677 | Cri | 0.64 | 9.8 | 0.09 | May 2, 2019 | The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection. | ||
| CVE-2019-8395 | Cri | 0.64 | 9.8 | 0.06 | Feb 17, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request. | ||
| CVE-2018-20664 | Cri | 0.64 | 9.8 | 0.07 | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. | ||
| CVE-2018-15168 | Cri | 0.64 | 9.8 | 0.04 | Aug 8, 2018 | A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request. | ||
| CVE-2018-11717 | Cri | 0.64 | 9.8 | 0.08 | Jul 16, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and… | ||
| CVE-2018-10466 | Cri | 0.64 | 9.8 | 0.16 | May 29, 2018 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. | ||
| CVE-2018-5341 | Cri | 0.64 | 9.8 | 0.07 | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts. | ||
| CVE-2018-5339 | Cri | 0.64 | 9.8 | 0.07 | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. | ||
| CVE-2018-5338 | Cri | 0.64 | 9.8 | 0.08 | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. | ||
| CVE-2018-5337 | Cri | 0.64 | 9.8 | 0.08 | Apr 18, 2018 | An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts. | ||
| CVE-2017-16924 | Cri | 0.64 | 9.8 | 0.08 | Feb 19, 2018 | Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL,… | ||
| CVE-2015-9107 | Cri | 0.64 | 9.8 | 0.04 | Aug 4, 2017 | Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor. | ||
| CVE-2025-3835 | Cri | 0.63 | 9.6 | 0.02 | Jun 9, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. | ||
| CVE-2023-47211 | Cri | 0.63 | 9.1 | 0.47 | Jan 8, 2024 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | ||
| CVE-2022-38772 | Hig | 0.63 | 8.8 | 0.78 | Aug 29, 2022 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature. | ||
| CVE-2022-37024 | Hig | 0.63 | 8.8 | 0.79 | Aug 10, 2022 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code… | ||
| CVE-2019-10008 | Hig | 0.62 | 8.8 | 0.22 | Apr 24, 2019 | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect… | ||
| CVE-2019-8394 | Med | 0.62 | 6.5 | 0.63 | KEV | Feb 17, 2019 | Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. | |
| CVE-2024-24409 | Hig | 0.61 | 8.8 | 0.06 | Nov 8, 2024 | Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | ||
| CVE-2022-29457 | Hig | 0.61 | 8.8 | 0.08 | Apr 18, 2022 | Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. | ||
| CVE-2021-44757 | Cri | 0.61 | 9.1 | 0.24 | Jan 18, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. | ||
| CVE-2020-16267 | Hig | 0.61 | 8.8 | 0.43 | Oct 6, 2020 | Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module. | ||
| CVE-2019-19774 | Hig | 0.61 | 8.8 | 0.13 | Dec 13, 2019 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing… | ||
| CVE-2019-15105 | Hig | 0.61 | 8.8 | 0.08 | Aug 16, 2019 | An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can… | ||
| CVE-2019-15104 | Hig | 0.61 | 8.8 | 0.08 | Aug 16, 2019 | An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently… | ||
| CVE-2017-16542 | Hig | 0.61 | 8.8 | 0.05 | Nov 5, 2017 | Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request. | ||
| CVE-2022-27908 | Hig | 0.60 | 8.8 | 0.36 | Apr 18, 2022 | Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. | ||
| CVE-2021-20130 | Hig | 0.60 | 8.8 | 0.33 | Oct 13, 2021 | ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface. | ||
| CVE-2020-28050 | Cri | 0.60 | 9.1 | 0.05 | Mar 5, 2021 | Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server. |
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
- risk 0.64cvss 9.8epss 0.05
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
- risk 0.64cvss 9.8epss 0.03
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
- risk 0.64cvss 8.8epss 0.79
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privileged user exports "User…
- risk 0.64cvss 9.8epss 0.07
Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send a NEWSCAN request to a listening agent on…
- risk 0.64cvss 9.8epss 0.05
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
- risk 0.64cvss 9.8epss 0.02
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
- risk 0.64cvss 9.1epss 0.60
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
- risk 0.64cvss 9.8epss 0.09
SQL Injection in Zoho ManageEngine Applications Manager 14 before 14560 allows an attacker to execute commands on the server via the MyPage.do template_resid parameter.
- risk 0.64cvss 9.8epss 0.04
In Zoho ManageEngine Application Manager 14.7 Build 14730 (before 14684, and between 14689 and 14750), the AlarmEscalation module is vulnerable to unauthenticated SQL Injection attack.
- risk 0.64cvss 9.8epss 0.08
The REST API in Zoho ManageEngine Applications Manager before build 14740 allows an unauthenticated SQL Injection via a crafted request, leading to Remote Code Execution.
- risk 0.64cvss 9.8epss 0.07
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a…
- risk 0.64cvss 9.8epss 0.08
Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this report because they expect CSV risk mitigation to be…
- risk 0.64cvss 9.8epss 0.10
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
- risk 0.64cvss 9.8epss 0.09
The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.09
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection.
- risk 0.64cvss 9.8epss 0.06
An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request.
- risk 0.64cvss 9.8epss 0.07
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
- risk 0.64cvss 9.8epss 0.04
A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.
- risk 0.64cvss 9.8epss 0.08
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base64 encoded Password/Username of AD accounts, the cleartext Password/Username and…
- risk 0.64cvss 9.8epss 0.16
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
- risk 0.64cvss 9.8epss 0.07
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts.
- risk 0.64cvss 9.8epss 0.07
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions.
- risk 0.64cvss 9.8epss 0.08
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism.
- risk 0.64cvss 9.8epss 0.08
An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts.
- risk 0.64cvss 9.8epss 0.08
Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable /client-data/<client_id>/collections/##/usermgmt.xml URL,…
- risk 0.64cvss 9.8epss 0.04
Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.
- risk 0.63cvss 9.6epss 0.02
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
- risk 0.63cvss 9.1epss 0.47
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
- risk 0.63cvss 8.8epss 0.78
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 125658, 126003, 126105, and 126120 allow authenticated users to make database changes that lead to remote code execution in the NMAP feature.
- risk 0.63cvss 8.8epss 0.79
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code…
- risk 0.62cvss 8.8epss 0.22
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the administrator username, with an arbitrary incorrect…
- risk 0.62cvss 6.5epss 0.63
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
- risk 0.61cvss 8.8epss 0.06
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
- risk 0.61cvss 8.8epss 0.08
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
- risk 0.61cvss 9.1epss 0.24
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
- risk 0.61cvss 8.8epss 0.43
Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the RCA module.
- risk 0.61cvss 8.8epss 0.13
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing…
- risk 0.61cvss 8.8epss 0.08
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can…
- risk 0.61cvss 8.8epss 0.08
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently…
- risk 0.61cvss 8.8epss 0.05
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.
- risk 0.60cvss 8.8epss 0.36
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
- risk 0.60cvss 8.8epss 0.33
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
- risk 0.60cvss 9.1epss 0.05
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
Page 3 of 12