Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Oct 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execution. |
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website. The attack targets your application's users and not the applicatio...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Sep 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Sep 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Sep 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Sep 30, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials are in the source code that corresponds to the DCBackupRestore JAR archive. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to unrestricted file upload, leading to remote code execution. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus before 7111 is vulnerable to unrestricted file which leads to Remote code execution. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 21, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 21, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Sep 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Sep 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Sep 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Sep 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Sep 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Sep 1, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass. |