← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
1Zohocorp
1Manageengine Supportcenter Plus
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Apr 5, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Apr 5, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
1Zohocorp
1Manageengine Key Manager Plus
Jun 17, 2026
Mar 2, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during ex...Show more
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.Show less
1Zohocorp
1Manageengine Sharepoint Manager Plus
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
1Zohocorp
1Manageengine Sharepoint Manager Plus
Jun 17, 2026
Mar 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 2, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
1Zohocorp
1Manageengine Key Manager Plus
Jun 17, 2026
Mar 1, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Jan 28, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Jan 27, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
1Zohocorp
2Manageengine Desktop Central
Manageengine Desktop Central Managed Service Providers
Jun 17, 2026
Jan 18, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
1Zohocorp
1Manageengine O365 Manager Plus
Jun 17, 2026
Jan 12, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
1Zohocorp
2Log360
Manageengine Cloud Security Plus
Jun 17, 2026
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
1Zohocorp
1Manageengine M365 Manager Plus
Jun 17, 2026
Jan 12, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Jan 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jan 3, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windo...Show more
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain.Show less