← Back

Zohocorp

zohocorp

550 CVEs • 69 products

Products (69)

Click to collapse
Toggle
Zoho Forms
zoho_forms
Webnms
webnms
Log360
log360

CVEs (550)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 27, 2024
N/A· v4
4.2 MEDIUM· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
May 27, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.
1Zohocorp
3Manageengine Servicedesk Plus
Manageengine Servicedesk Plus MspManageengine Supportcenter Plus
Jun 17, 2026
May 27, 2024
N/A· v4
2.4 LOW· v3
N/A· v2
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerabil...Show more
Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom Actions menu on the request details. This vulnerability can be exploited only by the SDAdmin role users.Show less
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 22, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the dashboard graph feature.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection in the aggregate reports search option.
1Zohocorp
1Manageengine Pam360
Jun 17, 2026
May 20, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other...Show more
Zohocorp ManageEngine PAM360 version 6601 is vulnerable to authorization vulnerability which allows a low-privileged user to perform admin actions. Note: This vulnerability affects only the PAM360 6600 version. No other versions are applicable to this vulnerability.Show less
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
May 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while getting aggregate report data.
1Zohocorp
1Manageengine Exchange Reporter Plus
Jun 17, 2026
Feb 16, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Feb 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Feb 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Feb 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Feb 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
1Zohocorp
1Manageengine Adaudit Plus
Jun 17, 2026
Jan 25, 2024
N/A· v4
2.7 LOW· v3
N/A· v2
Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
1Zohocorp
1Manageengine Servicedesk Plus Msp
Jun 17, 2026
Jan 18, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
1Zohocorp
1Manageengine Adselfservice Plus
Jun 17, 2026
Jan 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnera...Show more
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.Show less
1Zohocorp
7Manageengine Firewall Analyzer
Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 more
Jun 17, 2026
Jan 8, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB fil...Show more
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.Show less