Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jan 3, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows d...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Dec 23, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations. |
1Zohocorp 1Manageengine Pam360 Jun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required. |
1Zohocorp 1Manageengine Access Manager Plus Jun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state. |
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Dec 12, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Dec 9, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories. |
1Zohocorp 1Manageengine Network Configuration Manager Jun 17, 2026 Nov 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality. |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Nov 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor. |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Nov 30, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module. |
1Zohocorp 1Manageengine Supportcenter Plus Jun 17, 2026 Nov 30, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module. |
1Zohocorp 1Manageengine M365 Manager Plus Jun 17, 2026 Nov 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution. |
1Zohocorp 3Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspManageengine Supportcenter PlusJun 17, 2026 Nov 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servl...Show more |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Nov 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user c...Show more |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Nov 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Zoho Remote Access Plus Server Windows Desktop Binary fixed from 10.1.2121.1 is affected by incorrect access control. The installation directory is vulnerable to weak file permissions by allowing full control for Windows...Show more |
1Zohocorp 1Manageengine Adaudit Plus Jun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code execution. |
1Zohocorp 1Manageengine Patch Connect Plus Jun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution. |
1Zohocorp 1Manageengine Network Configuration Manager Jun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search. |
1Zohocorp 1Manageengine Network Configuration Manager Jun 17, 2026 Nov 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details search. |