← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Oct 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution.
1Zohocorp
1Zoho Crm Lead Magnet
Jun 17, 2026
Oct 5, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the applicatio...Show more
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.Show less
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Sep 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Sep 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Sep 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Sep 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 21, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 21, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Sep 21, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Sep 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Sep 10, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Sep 10, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Sep 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Sep 1, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Aug 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.