zohocorp

559 tracked vulnerabilities.

CVE-2020-15588 CRITICAL
ManageEngine Desktop Central < 10.0.561 - Remote Code Execution via Integer Overflow in InternetSendRequestEx
Jul 29, 2020
CVSS 9.8
EPSS 0.06
CVE-2020-14048 HIGH
ManageEngine ServiceDesk Plus < 11.1 build 11115 - Unauthenticated Agent Installation Status Manipulation
Jun 12, 2020
CVSS 7.5
EPSS 0.25
CVE-2020-13818 HIGH
ManageEngine OpManager < 125144 - Path Traversal via Cache Start Bypass
Jun 04, 2020
CVSS 7.5
EPSS 0.77
CVE-2020-13154 MEDIUM
Zoho ManageEngine Service Plus <11.1.11112 - Info Disclosure
May 18, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-11532 CRITICAL
ManageEngine ADAudit Plus Xnode Enumeration
May 08, 2020
CVSS 9.8
EPSS 0.90
CVE-2020-11531 HIGH
ManageEngine DataSecurity Plus < 6.0.1 - Path Traversal & RCE via DR-SCHEMA-SYNC
May 08, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-12116 HIGH NUCLEI
Zoho ManageEngine OpManger - Arbitrary File Read
May 07, 2020
CVSS 7.5
EPSS 0.92
CVE-2020-10859 MEDIUM
Zoho ManageEngine Desktop Central <10.0.484 - Path Traversal
May 05, 2020
CVSS 6.5
EPSS 0.04
CVE-2020-11946 HIGH
Zoho ManageEngine OpManager - Unauthenticated API Key Retrieval via Servlet Call
Apr 20, 2020
CVSS 7.5
EPSS 0.67
CVE-2020-11527 HIGH
Zoho ManageEngine OpManager <12.4.181 - Info Disclosure
Apr 04, 2020
CVSS 7.5
EPSS 0.14
CVE-2020-11518 CRITICAL
ManageEngine ADSelfService Plus < 5815 - Unauthenticated Remote Code Execution
Apr 04, 2020
CVSS 9.8
EPSS 0.10
CVE-2020-8509 HIGH
Zoho ManageEngine Desktop Central <10.0.483 - Info Disclosure
Mar 30, 2020
CVSS 7.5
EPSS 0.12
CVE-2020-8838 MEDIUM
Zoho ManageEngine AssetExplorer 6.5 - RCE
Mar 23, 2020
CVSS 6.4
EPSS 0.00
CVE-2020-9347 CRITICAL
Zoho ManageEngine Password Manager Pro <10.x - Code Injection
Mar 16, 2020
CVSS 9.8
EPSS 0.02
CVE-2020-9346 HIGH
ManageEngine Password Manager Pro <= 10.4 - Cross-Site Request Forgery
Mar 16, 2020
CVSS 8.8
EPSS 0.00
CVE-2020-10541 CRITICAL
Zoho ManageEngine OpManager <12.4.179 - RCE
Mar 13, 2020
CVSS 9.8
EPSS 0.02
CVE-2020-8540 CRITICAL
Zoho ManageEngine Desktop Central <07-Mar-2020 - SSRF
Mar 11, 2020
CVSS 9.8
EPSS 0.24
CVE-2020-10189 CRITICAL KEVNUCLEI
ManageEngine Desktop Central < 10.0.479 - Remote Code Execution via Java Deserialization in FileStorage
Mar 06, 2020
CVSS 9.8
EPSS 0.94
CVE-2020-8422 MEDIUM
Zoho ManageEngine Remote Access Plus <10.0.450 - Info Disclosure
Jan 31, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-6843 MEDIUM
ManageEngine ServiceDesk Plus < 11.0 - Cross-Site Scripting
Jan 23, 2020
CVSS 4.8
EPSS 0.02
CVE-2019-16268 MEDIUM
Zoho ManageEngine Remote Access Plus 10.0.259 - XSS
Feb 03, 2021
CVSS 4.8
EPSS 0.12
CVE-2019-16962 MEDIUM
Zoho ManageEngine Desktop Central 10.0.430 - Cross-Site Scripting via Custom Report Name
Jan 06, 2021
CVSS 5.4
EPSS 0.02
CVE-2019-15083 MEDIUM
ManageEngine ServiceDesk Plus < 10500 - Stored Cross-Site Scripting via Workstation Software Name
May 14, 2020
CVSS 6.1
EPSS 0.02
CVE-2019-19034 HIGH
Zoho ManageEngine Asset Explorer 6.5 - Command Injection
Mar 23, 2020
CVSS 7.2
EPSS 0.21
CVE-2019-15510 MEDIUM
Zoho ManageEngine Desktop Central 10 - Stored Cross-Site Scripting via Role Description
Mar 23, 2020
CVSS 6.1
EPSS 0.04