Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Analytics Plus Jun 17, 2026 Aug 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code. |
1Zohocorp 1Manageengine Analytics Plus Jun 17, 2026 Aug 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license...Show more |
1Zohocorp 7Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 moreJun 17, 2026 Aug 10, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated user...Show more |
1Zohocorp 7Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 moreJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow...Show more |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Jul 26, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.) |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Jul 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.) |
1Zohocorp 4Manageengine Firewall Analyzer Manageengine Netflow AnalyzerManageengine Network Configuration Manager+1 moreJun 17, 2026 Jul 18, 2022 N/A· v4 8.2 HIGH· v3 N/A· v2 ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine. |
1Zohocorp 4Manageengine Assetexplorer Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 moreJun 17, 2026 Jul 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (T...Show more |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jul 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API. |
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Jul 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml). |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 May 24, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 May 20, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 May 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Apr 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProd...Show more |
1Zohocorp 4Manageengine Adaudit Plus Manageengine Admanager PlusManageengine Adselfservice Plus+1 moreJun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Apr 18, 2022 N/A· v4 6.8 MEDIUM· v3 7.1 HIGH· v2 Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default ad...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 18, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Apr 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Apr 16, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator). |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Apr 7, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen. |