← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Analytics Plus
Jun 17, 2026
Aug 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
1Zohocorp
1Manageengine Analytics Plus
Jun 17, 2026
Aug 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license...Show more
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary files, enumerate folders and scan internal ports via crafted XML license file.Show less
1Zohocorp
7Manageengine Firewall Analyzer
Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 more
Jun 17, 2026
Aug 10, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated user...Show more
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) allow authenticated users to make database changes that lead to remote code execution.Show less
1Zohocorp
7Manageengine Firewall Analyzer
Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 more
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow...Show more
Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, Firewall Analyzer, and OpUtils before 2022-07-27 through 2022-07-28 (125657, 126002, 126104, and 126118) allow unauthenticated attackers to obtain a user's API key, and then access external APIs.Show less
1Zohocorp
1Manageengine Supportcenter Plus
Jun 17, 2026
Jul 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Jul 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)
1Zohocorp
4Manageengine Firewall Analyzer
Manageengine Netflow AnalyzerManageengine Network Configuration Manager+1 more
Jun 17, 2026
Jul 18, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
1Zohocorp
4Manageengine Assetexplorer
Manageengine Servicedesk PlusManageengine Servicedesk Plus Msp+1 more
Jun 17, 2026
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (T...Show more
Zoho ManageEngine ServiceDesk Plus before 13008, ServiceDesk Plus MSP before 10606, and SupportCenter Plus before 11022 are affected by an unauthenticated local file disclosure vulnerability via ticket-creation email. (This also affects Asset Explorer before 6977 with authentication.)Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jul 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload to the Mobile App Deployment API.
1Zohocorp
1Manageengine Servicedesk Plus Msp
Jun 17, 2026
Jul 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
May 24, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 20, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Apr 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProd...Show more
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.Show less
1Zohocorp
4Manageengine Adaudit Plus
Manageengine Admanager PlusManageengine Adselfservice Plus+1 more
Jun 17, 2026
Apr 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 18, 2022
N/A· v4
6.8 MEDIUM· v3
7.1 HIGH· v2
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default ad...Show more
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script feature. Due to the use of a default administrator password, attackers may be able to abuse this functionality with minimal effort. Additionally, a remote and partially authenticated attacker may be able to inject arbitrary commands into the custom script due to an unsanitized password field.Show less
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Apr 18, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Apr 16, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Apr 16, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Apr 7, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.