Vendor CVEs
Zohocorp
All CVEs
562 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-12542 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter. | ||
| CVE-2019-12541 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter. | ||
| CVE-2019-12538 | Med | 0.43 | 6.1 | 0.06 | Jun 5, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field. | ||
| CVE-2019-12189 | Med | 0.43 | 6.1 | 0.06 | May 21, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field. | ||
| CVE-2019-8928 | Med | 0.43 | 6.1 | 0.06 | May 17, 2019 | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName. | ||
| CVE-2019-8927 | Med | 0.43 | 6.1 | 0.06 | May 17, 2019 | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup,… | ||
| CVE-2019-8926 | Med | 0.43 | 6.1 | 0.06 | May 17, 2019 | An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource. | ||
| CVE-2017-9376 | Med | 0.43 | 6.5 | 0.07 | Mar 25, 2019 | ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do. | ||
| CVE-2018-20485 | Med | 0.43 | 6.1 | 0.05 | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature. | ||
| CVE-2018-20484 | Med | 0.43 | 6.1 | 0.05 | Dec 26, 2018 | Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation. | ||
| CVE-2018-15740 | Med | 0.43 | 6.1 | 0.06 | Aug 28, 2018 | Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen. | ||
| CVE-2015-7780 | Med | 0.43 | 6.5 | 0.11 | Jun 27, 2017 | Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0. | ||
| CVE-2025-11670 | Med | 0.42 | 6.4 | 0.00 | Dec 15, 2025 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled. | ||
| CVE-2025-9227 | Med | 0.42 | 6.5 | 0.00 | Nov 11, 2025 | Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor. | ||
| CVE-2025-6239 | Med | 0.42 | 6.5 | 0.01 | Oct 21, 2025 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | ||
| CVE-2025-27930 | Med | 0.42 | 6.4 | 0.00 | Jul 23, 2025 | Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor. | ||
| CVE-2025-3444 | Med | 0.42 | 6.5 | 0.01 | May 22, 2025 | Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. | ||
| CVE-2024-9100 | Med | 0.42 | 6.5 | 0.00 | Oct 3, 2024 | Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal. | ||
| CVE-2023-50891 | Med | 0.42 | 6.5 | 0.01 | Dec 29, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1. | ||
| CVE-2023-38332 | Med | 0.42 | 6.5 | 0.04 | Aug 4, 2023 | Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure. | ||
| CVE-2022-40772 | Med | 0.42 | 6.5 | 0.03 | Nov 23, 2022 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module. | ||
| CVE-2022-24447 | Med | 0.42 | 6.5 | 0.01 | Mar 2, 2022 | An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export. | ||
| CVE-2022-23863 | Med | 0.42 | 6.5 | 0.02 | Jan 28, 2022 | Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. | ||
| CVE-2021-46166 | Med | 0.42 | 6.5 | 0.03 | Jan 10, 2022 | Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page. | ||
| CVE-2021-35512 | Med | 0.42 | 6.5 | 0.02 | Oct 21, 2021 | An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200. | ||
| CVE-2021-37420 | Med | 0.42 | 6.5 | 0.02 | Sep 21, 2021 | Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. | ||
| CVE-2020-13154 | Med | 0.42 | 6.5 | 0.03 | May 18, 2020 | Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet. | ||
| CVE-2020-8838 | Med | 0.42 | 6.4 | 0.02 | Mar 23, 2020 | An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines… | ||
| CVE-2017-11561 | Med | 0.42 | 6.5 | 0.02 | May 23, 2019 | An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell. | ||
| CVE-2025-5347 | Med | 0.41 | 6.3 | 0.00 | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module. | ||
| CVE-2025-5343 | Med | 0.41 | 6.3 | 0.00 | Oct 30, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option. | ||
| CVE-2024-50053 | Med | 0.41 | 6.3 | 0.01 | Mar 21, 2025 | Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature. | ||
| CVE-2024-41150 | Med | 0.41 | 6.3 | 0.01 | Aug 23, 2024 | An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus:… | ||
| CVE-2024-27313 | Med | 0.41 | 6.3 | 0.01 | May 29, 2024 | Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610. | ||
| CVE-2021-31813 | Med | 0.41 | 5.4 | 0.78 | Jul 1, 2021 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. | ||
| CVE-2025-9787 | Med | 0.40 | 6.1 | 0.01 | Dec 18, 2025 | Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view. | ||
| CVE-2023-4768 | Med | 0.40 | 6.1 | 0.03 | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in… | ||
| CVE-2023-4767 | Med | 0.40 | 6.1 | 0.03 | Nov 3, 2023 | A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in… | ||
| CVE-2020-27449 | Med | 0.40 | 6.1 | 0.03 | Aug 11, 2023 | Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload. | ||
| CVE-2023-38333 | Med | 0.40 | 6.1 | 0.02 | Aug 10, 2023 | Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in. | ||
| CVE-2023-29442 | Med | 0.40 | 6.1 | 0.09 | Apr 26, 2023 | Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS. | ||
| CVE-2023-23078 | Med | 0.40 | 6.1 | 0.03 | Feb 1, 2023 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets. | ||
| CVE-2023-23077 | Med | 0.40 | 6.1 | 0.03 | Feb 1, 2023 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment. | ||
| CVE-2023-23075 | Med | 0.40 | 6.1 | 0.03 | Feb 1, 2023 | Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation. | ||
| CVE-2023-23073 | Med | 0.40 | 6.1 | 0.03 | Feb 1, 2023 | Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component. | ||
| CVE-2022-24681 | Med | 0.40 | 6.1 | 0.04 | Apr 7, 2022 | Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. | ||
| CVE-2021-43295 | Med | 0.40 | 6.1 | 0.03 | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. | ||
| CVE-2021-43294 | Med | 0.40 | 6.1 | 0.01 | Nov 30, 2021 | Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. | ||
| CVE-2021-37416 | Med | 0.40 | 6.1 | 0.03 | Aug 30, 2021 | Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. | ||
| CVE-2021-40178 | Med | 0.40 | 6.1 | 0.01 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings. |
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do userConfigID parameter.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SolutionSearch.do searchText parameter.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SiteLookup.do search field.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userManagementForm.jsp via these GET parameters: authMeth, passWord, pwd1, and userName.
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/scheduleConfig.jsp file via these GET parameters: devSrc, emailId, excWeekModify, filterFlag, getFilter, mailReport, mset, popup,…
- risk 0.43cvss 6.1epss 0.06
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zone /netflow/jspui/popup1.jsp file via these GET parameters: bussAlert, customDev, and selSource.
- risk 0.43cvss 6.5epss 0.07
ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do.
- risk 0.43cvss 6.1epss 0.05
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
- risk 0.43cvss 6.1epss 0.05
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
- risk 0.43cvss 6.1epss 0.06
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
- risk 0.43cvss 6.5epss 0.11
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
- risk 0.42cvss 6.4epss 0.00
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
- risk 0.42cvss 6.5epss 0.00
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
- risk 0.42cvss 6.5epss 0.01
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
- risk 0.42cvss 6.4epss 0.00
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
- risk 0.42cvss 6.5epss 0.01
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
- risk 0.42cvss 6.5epss 0.00
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.
- risk 0.42cvss 6.5epss 0.01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.
- risk 0.42cvss 6.5epss 0.04
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
- risk 0.42cvss 6.5epss 0.03
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.
- risk 0.42cvss 6.5epss 0.02
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
- risk 0.42cvss 6.5epss 0.03
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
- risk 0.42cvss 6.5epss 0.02
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
- risk 0.42cvss 6.5epss 0.02
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
- risk 0.42cvss 6.5epss 0.03
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
- risk 0.42cvss 6.4epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute code with NT AUTHORITY/SYSTEM privileges on the agent machines…
- risk 0.42cvss 6.5epss 0.02
An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
- risk 0.41cvss 6.3epss 0.00
Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.
- risk 0.41cvss 6.3epss 0.00
Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.
- risk 0.41cvss 6.3epss 0.01
Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
- risk 0.41cvss 6.3epss 0.01
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; ServiceDesk Plus MSP: through 14800; SupportCenter Plus:…
- risk 0.41cvss 6.3epss 0.01
Zoho ManageEngine PAM360 is vulnerable to Stored XSS vulnerability. This vulnerability is applicable only in the version 6610.
- risk 0.41cvss 5.4epss 0.78
Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD.
- risk 0.40cvss 6.1epss 0.01
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
- risk 0.40cvss 6.1epss 0.03
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…
- risk 0.40cvss 6.1epss 0.03
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in…
- risk 0.40cvss 6.1epss 0.03
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
- risk 0.40cvss 6.1epss 0.09
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
- risk 0.40cvss 6.1epss 0.03
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
- risk 0.40cvss 6.1epss 0.03
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
- risk 0.40cvss 6.1epss 0.03
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
- risk 0.40cvss 6.1epss 0.03
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
- risk 0.40cvss 6.1epss 0.04
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
Page 8 of 12