← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauth...Show more
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.Show less
1Zohocorp
1Manageengine Datasecurity Plus
Jun 17, 2026
Oct 9, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the passw...Show more
An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file of the mail server (except for the password).Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Aug 21, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
AjaxDomainServlet in Zoho ManageEngine ServiceDesk Plus 10 allows User Enumeration. NOTE: the vendor's position is that this is intended functionality
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For ex...Show more
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm' string is used for the password. For example, if the username is admin, the password is admin@opm.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can...Show more
An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Aug 16, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the...Show more
An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. Therefore, a low-authority user can gain the authority of SYSTEM on the server. One can consequently upload a malicious file using the "Execute Program Action(s)" feature.Show less
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over Service (FOS) replication, aka SD-79989.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Aug 8, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or...Show more
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.Show less
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Aug 8, 2019
N/A· v4
9.1 CRITICAL· v3
6.5 MEDIUM· v2
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer version 6.2.0 for the AJaxServlet servlet via a parameter in a URL.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Aug 8, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Server Side Request Forgery (SSRF) exists in Zoho ManageEngine AssetExplorer 6.2.0 and before for the ClientUtilServlet servlet via a URL in a parameter.
1Zohocorp
3Manageengine Admanager Plus
Manageengine Adselfservice PlusManageengine Desktop Central
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.3 HIGH· v3
8.5 HIGH· v2
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field.
1Zohocorp
1Manageengine Servicedesk Plus
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in the Purchase component of Zoho ManageEngine ServiceDesk Plus. There is XSS via the SearchN.do search field, a different vulnerability than CVE-2019-12189.
1Zohocorp
1Manageengine Assetexplorer
Jun 17, 2026
Jul 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
1Zohocorp
18Manageengine Analytics Plus
Manageengine Browser Security PlusManageengine Desktop Central+15 more
Jun 17, 2026
Jun 18, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said product...Show more
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM. This affects Desktop Central 10.0.380, EventLog Analyzer 12.0.2, ServiceDesk Plus 10.0.0, SupportCenter Plus 8.1, O365 Manager Plus 4.0, Mobile Device Manager Plus 9.0.0, Patch Connect Plus 9.0.0, Vulnerability Manager Plus 9.0.0, Patch Manager Plus 9.0.0, OpManager 12.3, NetFlow Analyzer 11.0, OpUtils 11.0, Network Configuration Manager 11.0, FireWall 12.0, Key Manager Plus 5.6, Password Manager Pro 9.9, Analytics Plus 1.0, and Browser Security Plus.Show less
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jun 17, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restr...Show more
An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus before 5.0.6 allows an attacker with physical access to gain a shell with SYSTEM privileges via the restricted thick client browser. The attack uses a long sequence of crafted keyboard input.Show less
1Zohocorp
1Manageengine Netflow Analyzer
Jun 17, 2026
Jun 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3 allows attackers to execute arbitrary SQL commands via the DeviceID parameter.