Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Aug 30, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Log360 before Build 5225 allows stored XSS. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings. |
1Zohocorp 1Manageengine Cloud Security Plus Jun 17, 2026 Aug 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings. |
1Zohocorp 1Manageengine Log360 Jun 17, 2026 Aug 29, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Aug 9, 2021 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse s...Show more |
1Zohocorp 1Manageengine Password Manager Pro Jun 17, 2026 Jul 31, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the...Show more |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Jul 19, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an...Show more |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Jul 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure their IP address to match the Asset Explorer's Server IP address. This will allow an attacker to send...Show more |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Jul 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Server. The HTTPS certificates are not verified which allows any arbitrary user on the network to send co...Show more |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Jul 17, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADManager Plus before 7110 allows stored XSS. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Jul 17, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADManager Plus before 7110 allows reflected XSS. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Jul 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADManager Plus before 7110 allows remote code execution. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jul 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information about the password-sync database application. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Jul 1, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (e.g., a crafted user name) from AD. |