← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) atta...Show more
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.Show less
1Zohocorp
1Manageengine Password Manager Pro
Nov 21, 2024
Mar 9, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.
1Zohocorp
1Manageengine Desktop Central
Jun 17, 2026
Mar 6, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUpload...Show more
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.Show less
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Feb 17, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to us...Show more
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.Show less
1Zohocorp
3Manageengine Applications Manager
Manageengine It360Manageengine Opmanager
Nov 21, 2024
Feb 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, w...Show more
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Feb 6, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Zoho ManageEngine Applications Manager 14 before 14520 allows a remote unauthenticated attacker to disclose OS file names via FailOverHelperServlet.
1Zohocorp
1Manageengine Remote Access Plus
Jun 17, 2026
Jan 31, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote...Show more
An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collection of all defined credentials of remote machines: the credential name, credential type, user name, domain/workgroup name, and description (but not the password).Show less
1Zohocorp
1Manageengine Desktop Central
Nov 21, 2024
Jan 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension,...Show more
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Jan 23, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Zoho ManageEngine ServiceDesk Plus 11.0 Build 11007 allows XSS. This issue was fixed in version 11.0 Build 11010, SD-83959.
1Zohocorp
2Manageengine Desktop Central
Manageengine Desktop Central Managed Service Providers
Nov 21, 2024
Jan 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to writ...Show more
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.Show less
1Zohocorp
1Manageengine Eventlog Analyzer
Nov 21, 2024
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
1Zohocorp
1Manageengine Eventlog Analyzer
Nov 21, 2024
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious...Show more
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Dec 31, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the system and modify the product installation.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Dec 18, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent to a specified external site.
1Zohocorp
1Manageengine Eventlog Analyzer
Jun 17, 2026
Dec 13, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restr...Show more
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Dec 11, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet agentid parameter to the Agent.java process function.
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Dec 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet function.
1Zohocorp
2Manageengine Firewall Analyzer
Manageengine Opmanager
Jun 17, 2026
Nov 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a mal...Show more
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Nov 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and...Show more
Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify their enrolled information, such as email and mobile phone, unintentionally. Attackers could use the reset password function and control the system to send the authentication code back to the channel that the attackers own.Show less