Vendor CVEs
Zohocorp
All CVEs
562 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40176 | Med | 0.40 | 6.1 | 0.01 | Aug 29, 2021 | Zoho ManageEngine Log360 before Build 5225 allows stored XSS. | ||
| CVE-2021-36772 | Med | 0.40 | 6.1 | 0.01 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. | ||
| CVE-2021-36771 | Med | 0.40 | 6.1 | 0.01 | Jul 17, 2021 | Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. | ||
| CVE-2021-27956 | Med | 0.40 | 6.1 | 0.02 | May 20, 2021 | Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. | ||
| CVE-2020-35594 | Med | 0.40 | 6.1 | 0.01 | Mar 5, 2021 | Zoho ManageEngine ADManager Plus before 7066 allows XSS. | ||
| CVE-2021-27214 | Med | 0.40 | 6.1 | 0.02 | Feb 19, 2021 | A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative… | ||
| CVE-2020-15521 | Med | 0.40 | 6.1 | 0.02 | Sep 25, 2020 | Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) . | ||
| CVE-2019-15510 | Med | 0.40 | 6.1 | 0.03 | Mar 23, 2020 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. | ||
| CVE-2019-18781 | Med | 0.40 | 6.1 | 0.02 | Dec 18, 2019 | An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site. | ||
| CVE-2019-12597 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName. | ||
| CVE-2019-12596 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType. | ||
| CVE-2019-12595 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter. | ||
| CVE-2019-12540 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. | ||
| CVE-2019-12539 | Med | 0.40 | 6.1 | 0.03 | Jul 11, 2019 | An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189. | ||
| CVE-2019-12537 | Med | 0.40 | 6.1 | 0.02 | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field. | ||
| CVE-2019-8346 | Med | 0.40 | 6.1 | 0.04 | May 24, 2019 | In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD… | ||
| CVE-2017-11739 | Med | 0.40 | 6.1 | 0.03 | May 23, 2019 | In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be… | ||
| CVE-2019-7427 | Med | 0.40 | 6.1 | 0.03 | May 7, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter. | ||
| CVE-2019-7426 | Med | 0.40 | 6.1 | 0.03 | May 7, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter. | ||
| CVE-2019-11676 | Med | 0.40 | 6.1 | 0.02 | May 2, 2019 | The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks. | ||
| CVE-2019-11511 | Med | 0.40 | 6.1 | 0.02 | Apr 25, 2019 | Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. | ||
| CVE-2019-7425 | Med | 0.40 | 6.1 | 0.03 | Mar 21, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter. | ||
| CVE-2019-7424 | Med | 0.40 | 6.1 | 0.03 | Mar 21, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is… | ||
| CVE-2019-7423 | Med | 0.40 | 6.1 | 0.03 | Mar 21, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter. | ||
| CVE-2019-7422 | Med | 0.40 | 6.1 | 0.03 | Mar 21, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter. | ||
| CVE-2018-20339 | Med | 0.40 | 6.1 | 0.02 | Dec 21, 2018 | Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section. | ||
| CVE-2018-19921 | Med | 0.40 | 6.1 | 0.02 | Dec 6, 2018 | Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller. | ||
| CVE-2018-18716 | Med | 0.40 | 6.1 | 0.03 | Nov 20, 2018 | Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability. | ||
| CVE-2018-18715 | Med | 0.40 | 6.1 | 0.03 | Nov 20, 2018 | Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. | ||
| CVE-2018-19288 | Med | 0.40 | 6.1 | 0.02 | Nov 15, 2018 | Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. | ||
| CVE-2018-18262 | Med | 0.40 | 6.1 | 0.02 | Oct 17, 2018 | Zoho ManageEngine OpManager 12.3 before build 123214 has XSS. | ||
| CVE-2018-17596 | Med | 0.40 | 6.1 | 0.02 | Oct 2, 2018 | In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter. | ||
| CVE-2018-16965 | Med | 0.40 | 6.1 | 0.03 | Sep 21, 2018 | In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter. | ||
| CVE-2018-15169 | Med | 0.40 | 6.1 | 0.02 | Aug 8, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter. | ||
| CVE-2018-10076 | Med | 0.40 | 6.1 | 0.01 | Jul 2, 2018 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard). | ||
| CVE-2018-10075 | Med | 0.40 | 6.1 | 0.01 | Jul 2, 2018 | Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature. | ||
| CVE-2018-12996 | Med | 0.40 | 6.1 | 0.03 | Jun 29, 2018 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do. | ||
| CVE-2018-10803 | Med | 0.40 | 6.1 | 0.01 | May 10, 2018 | Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through… | ||
| CVE-2018-5799 | Med | 0.40 | 6.1 | 0.02 | Mar 30, 2018 | In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139. | ||
| CVE-2018-8722 | Med | 0.40 | 6.1 | 0.02 | Mar 15, 2018 | Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. | ||
| CVE-2018-8721 | Med | 0.40 | 6.1 | 0.02 | Mar 15, 2018 | Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen | ||
| CVE-2018-7405 | Med | 0.40 | 6.1 | 0.01 | Mar 13, 2018 | Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2017-17698 | Med | 0.40 | 6.1 | 0.02 | Dec 15, 2017 | Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. | ||
| CVE-2017-11687 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2017 | Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog. | ||
| CVE-2017-11686 | Med | 0.40 | 6.1 | 0.02 | Jul 27, 2017 | Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method. | ||
| CVE-2017-11685 | Med | 0.40 | 6.1 | 0.01 | Jul 27, 2017 | Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter. | ||
| CVE-2022-43473 | Med | 0.39 | 5.8 | 0.20 | Mar 30, 2023 | A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability. | ||
| CVE-2021-46065 | Med | 0.39 | 4.8 | 0.92 | Jan 27, 2022 | A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code. | ||
| CVE-2021-31874 | Med | 0.39 | 5.9 | 0.04 | Jul 2, 2021 | Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application. | ||
| CVE-2021-31857 | Med | 0.39 | 5.9 | 0.03 | Jun 16, 2021 | In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types. |
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine ADManager Plus before 7110 allows stored XSS.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
- risk 0.40cvss 6.1epss 0.01
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
- risk 0.40cvss 6.1epss 0.02
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative…
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Applications Manager before 14 build 14730 has no protection against jsp/header.jsp Cross-site Scripting (XSS) .
- risk 0.40cvss 6.1epss 0.03
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
- risk 0.40cvss 6.1epss 0.03
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
- risk 0.40cvss 6.1epss 0.04
In Zoho ManageEngine ADSelfService Plus 5.x through 5704, an authorization.do cross-site Scripting (XSS) vulnerability allows for an unauthenticated manipulation of the JavaScript code by injecting the HTTP form parameter adscsrf. An attacker can use this to capture a user's AD…
- risk 0.40cvss 6.1epss 0.03
In Zoho ManageEngine Application Manager 13.1 Build 13100, an authenticated user, with administrative privileges, has the ability to add a widget on any dashboard. This widget can be a "Utility Widget" with a "Custom HTML or Text" field. Once this widget is created, it will be…
- risk 0.40cvss 6.1epss 0.03
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the autorefTime or graphTypes parameter.
- risk 0.40cvss 6.1epss 0.03
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter.
- risk 0.40cvss 6.1epss 0.02
The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
- risk 0.40cvss 6.1epss 0.03
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.
- risk 0.40cvss 6.1epss 0.03
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is…
- risk 0.40cvss 6.1epss 0.03
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.
- risk 0.40cvss 6.1epss 0.03
XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before 123237 has XSS in the domain controller.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine OpManager 12.3 before 123219 has a Self XSS Vulnerability.
- risk 0.40cvss 6.1epss 0.03
Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine OpManager 12.3 before build 123214 has XSS.
- risk 0.40cvss 6.1epss 0.02
In Zoho ManageEngine AssetExplorer, a Stored XSS vulnerability was discovered in the 6.2.0 version via the /AssetDef.do ciName or assetName parameter.
- risk 0.40cvss 6.1epss 0.03
In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.
- risk 0.40cvss 6.1epss 0.02
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality (the search box of the Dashboard).
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.
- risk 0.40cvss 6.1epss 0.03
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through…
- risk 0.40cvss 6.1epss 0.02
In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.
- risk 0.40cvss 6.1epss 0.01
Multiple Persistent cross-site scripting (XSS) vulnerabilities in Event log parsing and Display functions in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML via syslog.
- risk 0.40cvss 6.1epss 0.02
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible encoding method.
- risk 0.40cvss 6.1epss 0.01
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.
- risk 0.39cvss 5.8epss 0.20
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
- risk 0.39cvss 4.8epss 0.92
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
- risk 0.39cvss 5.9epss 0.04
Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application.
- risk 0.39cvss 5.9epss 0.03
In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.
Page 9 of 12