← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Jul 5, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jun 20, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain cont...Show more
Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby achieving the privileges of the domain controller administrator. NOTE: the vendor's perspective is that they have "found no evidence or detail of a security vulnerability."Show less
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
May 4, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Apr 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to mo...Show more
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.Show less
1Zohocorp
4Manageengine Assetexplorer
Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 more
Jun 17, 2026
Apr 26, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that...Show more
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 26, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Apr 13, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
1Zohocorp
3Manageengine Opmanager
Manageengine Opmanager MspManageengine Opmanager Plus
Jun 17, 2026
Mar 30, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payloa...Show more
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Mar 23, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
1Zohocorp
4Manageengine Assetexplorer
Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 more
Jun 17, 2026
Mar 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
1Zohocorp
4Manageengine Assetexplorer
Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 more
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Feb 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be...Show more
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)Show less
1Zohocorp
1Zoho Forms
Jun 17, 2026
Feb 13, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contrib...Show more
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
1Zohocorp
1Manageengine Supportcenter Plus
Jun 17, 2026
Feb 1, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Feb 1, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.