Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus before 11.1 build 11115 allows remote unauthenticated attackers to change the installation status of deployed agents. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Jun 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 May 18, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 May 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workstation local administrator. Using the installed program names of the computer as a vector, the local...Show more |
1Zohocorp 2Manageengine Adaudit Plus Manageengine Datasecurity PlusJun 17, 2026 May 8, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode server. This allows an attacker to bypass authentication for this server and execute all operations...Show more |
1Zohocorp 2Manageengine Adaudit Plus Manageengine Datasecurity PlusJun 17, 2026 May 8, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the database schema name when handling a DR-SCHEMA-SYNC request. This allows an authenticated attacker to ex...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 May 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 May 5, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Apr 4, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus before 5815 allows unauthenticated remote code execution. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure. |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Mar 23, 2020 N/A· v4 6.4 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attacker on an adjacent network to execute cod...Show more |
1Zohocorp 1Manageengine Assetexplorer Jun 17, 2026 Mar 23, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute...Show more |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. |
1Zohocorp 1Manageengine Remote Access Plus Jun 17, 2026 Mar 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escalation and eventually a full application takeover. |
1Zohocorp 1Manageengine Password Manager Pro Jun 17, 2026 Mar 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the vendor disputes the significance of this...Show more |
1Zohocorp 1Manageengine Password Manager Pro Jun 17, 2026 Mar 16, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Zoho ManageEngine Password Manager Pro 10.4 and prior has no protection against Cross-site Request Forgery (CSRF) attacks, as demonstrated by changing a user's role. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Mar 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Zoho ManageEngine Applications Manager before 14600 allows a remote unauthenticated attacker to disclose license related information via WieldFeedServlet servlet. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108. |