Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Jun 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10521 is vulnerable to Server-Side Request Forgery (SSRF). |
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure. |
1Zohocorp 2Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10521 allows an attacker to access internal data. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jun 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password. |
1Zohocorp 1Manageengine Password Manager Pro Jun 17, 2026 Jun 16, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types. |
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Jun 16, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Jun 10, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges. |
1Zohocorp 1Manageengine Key Manager Plus Jun 17, 2026 Jun 7, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious user details from AD. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 May 20, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Apr 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer before version 6800 allows a remote, unauthenticated attacker to conduct persistent cross-site scripti...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 1, 2021 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any direct...Show more |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 18, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Mar 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 11134 allows an Authentication Bypass (only during SAML login). |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Mar 5, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADManager Plus before 7066 allows XSS. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 5, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Zoho ManageEngine Desktop Central before build 10.0.647 allows a single authentication secret from multiple agents to communicate with the server. |
1Zohocorp 1Manageengine Applications Control Plus Jun 17, 2026 Mar 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Application Control Plus before 100523 has an insecure SSL configuration setting for Nginx, leading to Privilege Escalation. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Feb 19, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cr...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Feb 5, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 doFilter in com.adventnet.appmanager.filter.UriCollector in Zoho ManageEngine Applications Manager through 14930 allows an authenticated SQL Injection via the resourceid parameter to showresource.do. |