Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adaudit Plus Jun 17, 2026 Apr 5, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Apr 5, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Apr 5, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. |
1Zohocorp 1Manageengine Adaudit Plus Jun 17, 2026 Apr 5, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response. |
1Zohocorp 1Manageengine Key Manager Plus Jun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during ex...Show more |
1Zohocorp 1Manageengine Sharepoint Manager Plus Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled. |
1Zohocorp 1Manageengine Sharepoint Manager Plus Jun 17, 2026 Mar 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses. |
1Zohocorp 1Manageengine Key Manager Plus Jun 17, 2026 Mar 1, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Jan 28, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Jan 27, 2022 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code. |
1Zohocorp 2Manageengine Desktop Central Manageengine Desktop Central Managed Service ProvidersJun 17, 2026 Jan 18, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server. |
1Zohocorp 1Manageengine O365 Manager Plus Jun 17, 2026 Jan 12, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component. |
1Zohocorp 2Log360 Manageengine Cloud Security PlusJun 17, 2026 Jan 12, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175. |
1Zohocorp 1Manageengine M365 Manager Plus Jun 17, 2026 Jan 12, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Jan 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Jan 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jan 3, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windo...Show more |