Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 May 11, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint...Show more |
1Zohocorp 1Manageengine Netflow Analyzer Nov 21, 2024 May 10, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via...Show more |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: network services (Desktop Central and PostgreSQL) running with a superuser account. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: a missing server-side check on the file type/extension when uploading and modifying scripts. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: database access using a superuser account (specifically, an account with permission to write to the filesystem via SQL queries). |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: insufficient enforcement of database query type restrictions. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: missing authentication/authorization for a database query mechanism. |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Zoho ManageEngine Desktop Central 10.0.124 and 10.0.184: directory traversal in the SCRIPT_NAME field when modifying existing scripts. |
1Zohocorp 1Manageengine Recovery Manager Plus Jun 17, 2026 Apr 2, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script...Show more |
1Zohocorp 1Manageengine Servicedesk Plus Jun 17, 2026 Mar 30, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139. |
1Zohocorp 1Manageengine Desktop Central Jun 17, 2026 Mar 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026. |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Mar 15, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Mar 13, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied crede...Show more |
1Zohocorp 1Manageengine Desktop Central Nov 21, 2024 Feb 19, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Remote Information Disclosure and Escalation of Privileges in ManageEngine Desktop Central MSP 10.0.137 allows attackers to download unencrypted XML files containing all data for configuration policies via a predictable...Show more |
1Zohocorp 1Manageengine Admanager Plus Oct 24, 2025 Feb 7, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicio...Show more |
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action. |
1Zohocorp 1Manageengine Password Manager Pro May 13, 2026 Dec 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter. |
1Zohocorp 1Manageengine Applications Manager May 13, 2026 Nov 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a getResourceProfiles action. |