zohocorp

559 tracked vulnerabilities.

CVE-2021-37761 CRITICAL
Zoho ManageEngine ADManager Plus <= 7110 - Unrestricted File Upload leading to Remote Code Execution
Sep 27, 2021
CVSS 9.8
EPSS 0.37
CVE-2021-37539 CRITICAL
Zoho ManageEngine ADManager Plus < 7111 - Unrestricted File Upload leading to Remote Code Execution
Sep 27, 2021
CVSS 9.8
EPSS 0.36
CVE-2021-37927 CRITICAL
ManageEngine ADManager Plus <= 7110 - Account Takeover via SSO
Sep 22, 2021
CVSS 9.8
EPSS 0.02
CVE-2021-37925 CRITICAL
ManageEngine ADManager Plus <= 7110 - Authenticated OS Command Injection
Sep 22, 2021
CVSS 9.8
EPSS 0.21
CVE-2021-37741 HIGH
ManageEngine ADManager Plus < 7111 - Unauthenticated Remote Code Execution via Unrestricted File Upload
Sep 21, 2021
CVSS 8.8
EPSS 0.05
CVE-2021-37424 CRITICAL
ManageEngine ADSelfService Plus <6.1.12 - Info Disclosure
Sep 21, 2021
CVSS 9.8
EPSS 0.14
CVE-2021-37420 MEDIUM
ManageEngine ADSelfService Plus < 6112 - Unauthenticated Mail Spoofing
Sep 21, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-37419 HIGH
ManageEngine ADSelfService Plus < 6112 - Server-Side Request Forgery
Sep 21, 2021
CVSS 7.5
EPSS 0.08
CVE-2021-37422 CRITICAL
ManageEngine ADSelfService Plus <= 6111 - SQL Injection
Sep 10, 2021
CVSS 9.8
EPSS 0.26
CVE-2021-37423 CRITICAL
Zoho ManageEngine ADSelfService Plus <6.11 - SSRF
Sep 10, 2021
CVSS 9.8
EPSS 0.21
CVE-2021-37414 HIGH
ManageEngine Desktop Central < 10.0.709 - Unauthenticated API Key Disclosure
Sep 10, 2021
CVSS 7.5
EPSS 0.02
CVE-2021-40539 CRITICAL KEVNUCLEI
ManageEngine ADSelfService Plus CVE-2021-40539
Sep 07, 2021
CVSS 9.8
EPSS 0.94
CVE-2021-37415 CRITICAL KEVNUCLEI
Zoho ManageEngine ServiceDesk Plus < 11302 - Unauthenticated Authentication Bypass via REST-API URLs
Sep 01, 2021
CVSS 9.8
EPSS 0.93
CVE-2021-37421 CRITICAL
Zoho ManageEngine ADSelfService Plus < 6.1 - Admin Portal Access-Restriction Bypass
Aug 30, 2021
CVSS 9.8
EPSS 0.09
CVE-2021-37417 CRITICAL
Zoho ManageEngine ADSelfService Plus < 6.1 - CAPTCHA Bypass via Improper Parameter Validation
Aug 30, 2021
CVSS 9.8
EPSS 0.19
CVE-2021-37416 MEDIUM NUCLEI
ManageEngine ADSelfService Plus <= 6103 - Reflected Cross-Site Scripting via Loadframe Page
Aug 30, 2021
CVSS 6.1
EPSS 0.09
CVE-2021-33055 CRITICAL
Zoho ManageEngine ADSelfService Plus <6102 - RCE
Aug 30, 2021
CVSS 9.8
EPSS 0.22
CVE-2021-40178 MEDIUM
Zoho ManageEngine Log360 <Build 5224 - XSS
Aug 29, 2021
CVSS 6.1
EPSS 0.04
CVE-2021-40177 CRITICAL
Zoho ManageEngine Log360 <Build 5225 - RCE
Aug 29, 2021
CVSS 9.8
EPSS 0.07
CVE-2021-40176 MEDIUM
Zoho ManageEngine Log360 <Build 5225 - XSS
Aug 29, 2021
CVSS 6.1
EPSS 0.04
CVE-2021-40175 CRITICAL
Zoho ManageEngine Log360 <Build 5219 - RCE
Aug 29, 2021
CVSS 9.8
EPSS 0.09
CVE-2021-40174 HIGH
Zoho ManageEngine Log360 <Build 5224 - CSRF
Aug 29, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-40173 HIGH
Zoho ManageEngine Cloud Security Plus < 4.0 - Cross-Site Request Forgery in Server Proxy Settings
Aug 29, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-40172 HIGH
ManageEngine Log360 < 5.1 - Cross-Site Request Forgery in Proxy Settings
Aug 29, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-33256 HIGH
ManageEngine ADSelfService Plus <6.1.6101 - CSV Injection
Aug 09, 2021
CVSS 8.8
EPSS 0.16