Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
Total 511 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-7248 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-11-07 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.
CVE-2020-27449 1 Zohocorp 1 Manageengine Password Manager Pro 2023-08-16 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and steal cookies via crafted JavaScript payload.
CVE-2023-38332 1 Zohocorp 1 Manageengine Admanager Plus 2023-08-09 N/A 6.5 MEDIUM
Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.
CVE-2021-20148 1 Zohocorp 1 Manageengine Adselfservice Plus 2023-08-08 3.5 LOW 4.3 MEDIUM
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain can obtain the password policy for another domain by authenticating to the service and then sending a request specifying the password policy file of the other domain.
CVE-2022-24978 1 Zohocorp 1 Manageengine Adaudit Plus 2023-08-08 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
CVE-2022-23863 1 Zohocorp 1 Manageengine Desktop Central 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
CVE-2022-35404 1 Zohocorp 4 Manageengine Firewall Analyzer, Manageengine Netflow Analyzer, Manageengine Network Configuration Manager and 1 more 2023-08-08 N/A 8.2 HIGH
ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
CVE-2022-26777 1 Zohocorp 1 Manageengine Remote Access Plus 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view license details.
CVE-2022-23050 1 Zohocorp 1 Manageengine Applications Manager 2023-08-08 6.5 MEDIUM 7.2 HIGH
ManageEngine AppManager15 (Build No:15510) allows an authenticated admin user to upload a DLL file to perform a DLL hijack attack inside the 'working' folder through the 'Upload Files / Binaries' functionality.
CVE-2021-44676 1 Zohocorp 1 Manageengine Access Manager Plus 2023-08-08 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g., access control details) and modify a few aspects of the application state.
CVE-2022-24305 1 Zohocorp 1 Manageengine Sharepoint Manager Plus 2023-08-08 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
CVE-2021-44525 1 Zohocorp 1 Manageengine Pam360 2023-08-08 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of application state because of a filter bypass in which authentication is not required.
CVE-2022-25245 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name.
CVE-2022-26653 1 Zohocorp 1 Manageengine Remote Access Plus 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine Remote Access Plus before 10.1.2137.15 allows guest users to view domain details (such as the username and GUID of an administrator).
CVE-2023-38331 1 Zohocorp 1 Manageengine Supportcenter Plus 2023-08-03 N/A 5.4 MEDIUM
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
CVE-2023-37308 1 Zohocorp 1 Manageengine Adaudit Plus 2023-07-12 N/A 5.4 MEDIUM
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
CVE-2023-35786 1 Zohocorp 1 Manageengine Admanager Plus 2023-07-10 N/A 4.9 MEDIUM
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
CVE-2021-42847 1 Zohocorp 1 Manageengine Adaudit Plus 2023-05-09 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
CVE-2022-36413 1 Zohocorp 1 Manageengine Adselfservice Plus 2023-03-30 N/A 9.1 CRITICAL
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
CVE-2023-26601 1 Zohocorp 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more 2023-03-13 N/A 7.5 HIGH
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).