VYPR

Vendor CVEs

Zohocorp

All CVEs

568 total · sorted by risk
  • CVE-2020-15927HigOct 6, 2020
    risk 0.60cvss 8.8epss 0.43

    Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

  • CVE-2019-12994CriAug 8, 2019
    risk 0.60cvss 9.1epss 0.04

    Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.

  • CVE-2018-11808CriJun 6, 2018
    risk 0.60cvss 9.1epss 0.07

    Incorrect Access Control in CustomFieldsFeedServlet in Zoho ManageEngine Applications Manager Version 13 before build 13740 allows an attacker to delete any file and read certain files on the server in the context of the user (which by default is "NT AUTHORITY / SYSTEM") by…

  • CVE-2016-6601HigJan 23, 2017
    risk 0.60cvss 7.5epss 0.97

    Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

  • CVE-2025-11250CriJan 13, 2026
    risk 0.59cvss 9.1epss 0.02

    Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

  • CVE-2022-36413CriMar 23, 2023
    risk 0.59cvss 9.1epss 0.03

    Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.

  • CVE-2023-22964CriJan 20, 2023
    risk 0.59cvss 9.1epss 0.02

    Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.

  • CVE-2020-35765HigFeb 5, 2021
    risk 0.59cvss 8.8epss 0.27

    doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.

  • CVE-2019-7162CriDec 31, 2019
    risk 0.59cvss 9.1epss 0.04

    An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation.

  • CVE-2025-9223HigNov 11, 2025
    risk 0.58cvss 8.8epss 0.04

    Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

  • CVE-2024-5466HigAug 23, 2024
    risk 0.58cvss 8.8epss 0.07

    Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

  • CVE-2024-0252HigJan 11, 2024
    risk 0.58cvss 8.8epss 0.08

    ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

  • CVE-2023-29084HigApr 13, 2023
    risk 0.58cvss 7.2epss 0.98

    Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.

  • CVE-2022-48362HigFeb 25, 2023
    risk 0.58cvss 8.8epss 0.09

    Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker…

  • CVE-2022-40773HigNov 12, 2022
    risk 0.58cvss 8.8epss 0.05

    Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation. This allows users to obtain sensitive data during an exportMickeyList export of requests from the list view.

  • CVE-2021-44651HigJan 12, 2022
    risk 0.58cvss 8.8epss 0.05

    Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.

  • CVE-2021-46164HigJan 10, 2022
    risk 0.58cvss 8.8epss 0.07

    Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.

  • CVE-2021-20131HigOct 13, 2021
    risk 0.58cvss 8.8epss 0.17

    ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.

  • CVE-2020-35682HigMar 13, 2021
    risk 0.58cvss 8.8epss 0.07

    Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).

  • CVE-2020-27733HigJan 19, 2021
    risk 0.58cvss 8.8epss 0.09

    Zoho ManageEngine Applications Manager before 14 build 14880 allows an authenticated SQL Injection via a crafted Alarmview request.

  • CVE-2020-11531HigMay 8, 2020
    risk 0.58cvss 8.8epss 0.14

    The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to execute code in the context of the product by writing a JSP…

  • CVE-2014-7863HigFeb 8, 2020
    risk 0.58cvss 7.5epss 0.83

    The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users…

  • CVE-2014-6038HigJan 13, 2020
    risk 0.58cvss 7.5epss 0.73

    Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

  • CVE-2019-19650HigDec 11, 2019
    risk 0.58cvss 8.8epss 0.06

    Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.

  • CVE-2017-9362HigMar 25, 2019
    risk 0.58cvss 8.8epss 0.05

    ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

  • CVE-2017-14123HigSep 4, 2017
    risk 0.58cvss 8.8epss 0.06

    Zoho ManageEngine Firewall Analyzer 12200 has an unrestricted File Upload vulnerability in the "Group Chat" section. Any user can upload files with any extensions. By uploading a PHP file to the server, an attacker can cause it to execute in the server context, as demonstrated…

  • CVE-2026-12263HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.01

    Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.

  • CVE-2026-11840HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.02

    Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.

  • CVE-2024-5471HigJul 17, 2024
    risk 0.57cvss 8.8epss 0.02

    Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.

  • CVE-2022-41978HigNov 9, 2022
    risk 0.57cvss 8.8epss 0.03

    Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress.

  • CVE-2022-24978HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.

  • CVE-2020-28679HigJan 10, 2022
    risk 0.57cvss 8.8epss 0.03

    A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.

  • CVE-2021-37741HigSep 21, 2021
    risk 0.57cvss 8.8epss 0.03

    ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.

  • CVE-2021-40174HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.

  • CVE-2021-40173HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.

  • CVE-2021-40172HigAug 29, 2021
    risk 0.57cvss 8.8epss 0.01

    Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.

  • CVE-2020-12116HigMay 7, 2020
    risk 0.57cvss 7.5epss 0.97

    Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

  • CVE-2019-11361HigMar 19, 2020
    risk 0.57cvss 8.8epss 0.03

    Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover.

  • CVE-2020-9346HigMar 16, 2020
    risk 0.57cvss 8.8epss 0.02

    Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role.

  • CVE-2014-6039HigJan 13, 2020
    risk 0.57cvss 7.5epss 0.69

    ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

  • CVE-2019-19475HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can…

  • CVE-2019-18411HigNov 6, 2019
    risk 0.57cvss 8.8epss 0.02

    Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the…

  • CVE-2019-12959HigAug 8, 2019
    risk 0.57cvss 8.8epss 0.04

    Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.

  • CVE-2017-11740HigMay 23, 2019
    risk 0.57cvss 8.8epss 0.03

    In Zoho ManageEngine Application Manager 13.1 Build 13100, the administrative user has the ability to upload files/binaries that can be executed upon the occurrence of an alarm. An attacker can abuse this functionality by uploading a malicious script that can be executed on the…

  • CVE-2018-13411HigSep 12, 2018
    risk 0.57cvss 8.8epss 0.04

    An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud, the issue is fixed in 10.0.470 agent version.

  • CVE-2016-9489HigJul 13, 2018
    risk 0.57cvss 8.8epss 0.02

    In ManageEngine Applications Manager 12 and 13 before build 13200, an authenticated user is able to alter all of their own properties, including own group, i.e. changing their group to one with higher privileges like "ADMIN". A user is also able to change properties of another…

  • CVE-2017-17552HigFeb 7, 2018
    risk 0.57cvss 8.8epss 0.02

    /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.

  • CVE-2016-4889HigApr 14, 2017
    risk 0.57cvss 8.8epss 0.03

    ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict access to unknown functions.

  • CVE-2026-75791HigSep 22, 2026
    risk 0.56cvss 8.6epss —

    Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

  • CVE-2025-10020HigOct 21, 2025
    risk 0.56cvss 8.5epss 0.05

    Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

Page 4 of 12