Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Oct 27, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent to...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Oct 21, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Oct 21, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component. |
1Zohocorp 1Manageengine Analytics Plus Jun 17, 2026 Oct 21, 2025 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Oct 21, 2025 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Oct 21, 2025 N/A· v4 3.3 LOW· v3 N/A· v2 ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Sep 25, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup.
This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Jul 23, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Jun 26, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Jun 26, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report. |
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Jun 9, 2025 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module. |
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. |
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. |
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. |
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. |
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data. |
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report. |
1Zohocorp 2Manageengine Servicedesk Plus Msp Manageengine Supportcenter PlusJun 17, 2026 May 22, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded. |
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. |