← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Servicedesk Plus Msp
Jun 17, 2026
Jun 29, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF).
1Zohocorp
1Manageengine Servicedesk Plus Msp
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.
1Zohocorp
2Manageengine Servicedesk Plus
Manageengine Servicedesk Plus Msp
Jun 17, 2026
Jun 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jun 25, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.
1Zohocorp
1Manageengine Password Manager Pro
Jun 17, 2026
Jun 16, 2021
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.
1Zohocorp
1Manageengine Servicedesk Plus Msp
Jun 17, 2026
Jun 16, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Jun 10, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.
1Zohocorp
1Manageengine Key Manager Plus
Jun 17, 2026
Jun 7, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 20, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field.
1Zohocorp
1Manageengine Eventlog Analyzer
Jun 17, 2026
Apr 30, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Apr 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Apr 9, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripti...Show more
Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks by uploading a crafted XML asset file.Show less
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Apr 1, 2021
N/A· v4
9.1 CRITICAL· v3
9.4 HIGH· v2
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any direct...Show more
Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.Show less
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is...Show more
The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code, leading to an escalation of privilege to NT AUTHORITY\SYSTEM.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Mar 13, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login).
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Mar 5, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Zoho ManageEngine ADManager Plus before 7066 allows XSS.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 5, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server.
1Zohocorp
1Manageengine Applications Control Plus
Jun 17, 2026
Mar 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Feb 19, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cr...Show more
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Feb 5, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do.