← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Oct 27, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent to...Show more
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Oct 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Oct 21, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
1Zohocorp
1Manageengine Analytics Plus
Jun 17, 2026
Oct 21, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Oct 21, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Oct 21, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component.
1Zohocorp
1Manageengine Endpoint Central
Jun 17, 2026
Sep 25, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jul 23, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Jun 26, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Jun 26, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Jun 9, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Jun 9, 2025
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Jun 9, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Jun 9, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 23, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 23, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 22, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 22, 2025
N/A· v4
8.3 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.
1Zohocorp
2Manageengine Servicedesk Plus Msp
Manageengine Supportcenter Plus
Jun 17, 2026
May 22, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 14, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.