Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 May 7, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the groupDesc, groupName, groupID, or task parameter. |
1Zohocorp 1Manageengine Firewall Analyzer Jun 17, 2026 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injection. |
1Zohocorp 1Manageengine Firewall Analyzer Jun 17, 2026 May 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection. |
1Zohocorp 1Manageengine Firewall Analyzer Jun 17, 2026 May 2, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS attacks. |
1Zohocorp 1Manageengine Admanager Plus Nov 21, 2024 Apr 30, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Apr 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. |
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically converted into an established administrator session when the guest user enters the...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Apr 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequently, an unauthenticated user can gain the authority of SYSTEM on the server by uploading a malicious...Show more |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain the authority of SYSTEM on the server due to a Popup_SLA.jsp sid SQL injection vulnerability. For exam...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Apr 4, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an a...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Nov 21, 2024 Mar 25, 2019 N/A· v4 6.5 MEDIUM· v3 5.0 MEDIUM· v2 ManageEngine ServiceDesk Plus before 9314 contains a local file inclusion vulnerability in the defModule parameter in DefaultConfigDef.do and AssetDefaultConfigDef.do. |
1Zohocorp 1Manageengine Servicedesk Plus Nov 21, 2024 Mar 25, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot,...Show more |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 Mar 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to protect information, giving the capacity for an attacker to decipher any protected data. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Feb 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10007 via an attachment to a request. |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Feb 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Jan 3, 2019 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. |