VYPR

Vendor CVEs

Zohocorp

All CVEs

562 total · sorted by risk
  • CVE-2019-12542MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.

  • CVE-2019-12541MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.

  • CVE-2019-12538MedJun 5, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.

  • CVE-2019-12189MedMay 21, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.

  • CVE-2019-8928MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.

  • CVE-2019-8927MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup,…

  • CVE-2019-8926MedMay 17, 2019
    risk 0.43cvss 6.1epss 0.06

    An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.

  • CVE-2017-9376MedMar 25, 2019
    risk 0.43cvss 6.5epss 0.07

    ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.

  • CVE-2018-20485MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

  • CVE-2018-20484MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

  • CVE-2018-15740MedAug 28, 2018
    risk 0.43cvss 6.1epss 0.06

    Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

  • CVE-2015-7780MedJun 27, 2017
    risk 0.43cvss 6.5epss 0.11

    Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.

  • CVE-2025-11670MedDec 15, 2025
    risk 0.42cvss 6.4epss 0.00

    Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

  • CVE-2025-9227MedNov 11, 2025
    risk 0.42cvss 6.5epss 0.00

    Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.

  • CVE-2025-6239MedOct 21, 2025
    risk 0.42cvss 6.5epss 0.01

    Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

  • CVE-2025-27930MedJul 23, 2025
    risk 0.42cvss 6.4epss 0.00

    Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

  • CVE-2025-3444MedMay 22, 2025
    risk 0.42cvss 6.5epss 0.01

    Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

  • CVE-2024-9100MedOct 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

  • CVE-2023-50891MedDec 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.

  • CVE-2023-38332MedAug 4, 2023
    risk 0.42cvss 6.5epss 0.04

    Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

  • CVE-2022-40772MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.03

    Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.

  • CVE-2022-24447MedMar 2, 2022
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.

  • CVE-2022-23863MedJan 28, 2022
    risk 0.42cvss 6.5epss 0.02

    Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.

  • CVE-2021-46166MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.03

    Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.

  • CVE-2021-35512MedOct 21, 2021
    risk 0.42cvss 6.5epss 0.02

    An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.

  • CVE-2021-37420MedSep 21, 2021
    risk 0.42cvss 6.5epss 0.02

    Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

  • CVE-2020-13154MedMay 18, 2020
    risk 0.42cvss 6.5epss 0.03

    Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.

  • CVE-2020-8838MedMar 23, 2020
    risk 0.42cvss 6.4epss 0.02

    An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines…

  • CVE-2017-11561MedMay 23, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.

  • CVE-2025-5347MedOct 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.

  • CVE-2025-5343MedOct 30, 2025
    risk 0.41cvss 6.3epss 0.00

    Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

  • CVE-2024-50053MedMar 21, 2025
    risk 0.41cvss 6.3epss 0.01

    Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.

  • CVE-2024-41150MedAug 23, 2024
    risk 0.41cvss 6.3epss 0.01

    An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus:…

  • CVE-2024-27313MedMay 29, 2024
    risk 0.41cvss 6.3epss 0.01

    Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.

  • CVE-2021-31813MedJul 1, 2021
    risk 0.41cvss 5.4epss 0.78

    Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.

  • CVE-2025-9787MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.01

    Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

  • CVE-2023-4768MedNov 3, 2023
    risk 0.40cvss 6.1epss 0.03

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…

  • CVE-2023-4767MedNov 3, 2023
    risk 0.40cvss 6.1epss 0.03

    A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…

  • CVE-2020-27449MedAug 11, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.

  • CVE-2023-38333MedAug 10, 2023
    risk 0.40cvss 6.1epss 0.02

    Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.

  • CVE-2023-29442MedApr 26, 2023
    risk 0.40cvss 6.1epss 0.09

    Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.

  • CVE-2023-23078MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.

  • CVE-2023-23077MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.

  • CVE-2023-23075MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.

  • CVE-2023-23073MedFeb 1, 2023
    risk 0.40cvss 6.1epss 0.03

    Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.

  • CVE-2022-24681MedApr 7, 2022
    risk 0.40cvss 6.1epss 0.04

    Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.

  • CVE-2021-43295MedNov 30, 2021
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.

  • CVE-2021-43294MedNov 30, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.

  • CVE-2021-37416MedAug 30, 2021
    risk 0.40cvss 6.1epss 0.03

    Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.

  • CVE-2021-40178MedAug 29, 2021
    risk 0.40cvss 6.1epss 0.01

    Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.

Page 8 of 12