zohocorp

559 tracked vulnerabilities.

CVE-2025-5347 MEDIUM
ManageEngine Exchange Reporter Plus < 5723 - Stored Cross-Site Scripting in Reports Module
Oct 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-5343 MEDIUM
ManageEngine Exchange Reporter Plus <= 5721 - Stored Cross-Site Scripting in Instant Search
Oct 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-5342 MEDIUM
ManageEngine Exchange Reporter Plus <= 5721 - Denial of Service via Search Module ReDOS
Oct 30, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-11248 LOW
ZohoCorp ManageEngine Endpoint Central <11.4.2528.05 - Info Disclosure
Oct 27, 2025
CVSS 3.2
EPSS 0.00
CVE-2025-6239 MEDIUM
Zohocorp ManageEngine Applications Manager <176800 - Info Disclosure
Oct 21, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10020 HIGH
ManageEngine ADManager Plus < 8024 - Authenticated Command Injection in Custom Script
Oct 21, 2025
CVSS 8.5
EPSS 0.01
CVE-2025-9428 HIGH
ManageEngine Analytics Plus <= 6171 - Authenticated SQL Injection via Key Update API
Oct 21, 2025
CVSS 8.3
EPSS 0.02
CVE-2025-7473 MEDIUM
Zohocorp ManageEngine EndPoint Central <11.4.2516.1 - XML Injection
Oct 21, 2025
CVSS 5.2
EPSS 0.00
CVE-2025-5496 LOW
Zohocorp Manageengine Endpoint Central < 11.4.2508.14 - Improper Privilege Management
Oct 21, 2025
CVSS 3.3
EPSS 0.00
CVE-2025-5494 LOW
Zohocorp Manageengine Endpoint Central < 11.4.2500.26 - Improper Privilege Management
Sep 25, 2025
CVSS 3.9
EPSS 0.00
CVE-2025-27930 MEDIUM
ManageEngine Applications Manager <= 176600 - Stored Cross-Site Scripting in File/Directory Monitor
Jul 23, 2025
CVSS 6.4
EPSS 0.00
CVE-2025-5966 HIGH
ManageEngine Exchange Reporter Plus <= 5722 - Stored Cross-Site Scripting in Attachments by Filename Report
Jun 26, 2025
CVSS 8.1
EPSS 0.10
CVE-2025-5366 HIGH
ManageEngine Exchange Reporter Plus <= 5722 - Stored Cross-Site Scripting in Folder-wise Read Mails Report
Jun 26, 2025
CVSS 8.1
EPSS 0.10
CVE-2025-41444 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Alerts Module
Jun 09, 2025
CVSS 8.3
EPSS 0.04
CVE-2025-3835 CRITICAL
ManageEngine Exchange Reporter Plus <= 5721 - Remote Code Execution in Content Search Module
Jun 09, 2025
CVSS 9.6
EPSS 0.06
CVE-2025-36528 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Service Account Auditing Reports
Jun 09, 2025
CVSS 8.3
EPSS 0.04
CVE-2025-27709 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Service Account Auditing Reports
Jun 09, 2025
CVSS 8.3
EPSS 0.04
CVE-2025-41407 HIGH
ManageEngine ADAudit Plus < 8511 - SQL Injection in OU History Report
May 23, 2025
CVSS 8.3
EPSS 0.02
CVE-2025-36527 HIGH
ManageEngine ADAudit Plus < 8511 - SQL Injection via Report Export
May 23, 2025
CVSS 8.3
EPSS 0.05
CVE-2025-41403 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection
May 22, 2025
CVSS 8.3
EPSS 0.04
CVE-2025-3836 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in Logon Events Aggregate Report
May 22, 2025
CVSS 8.3
EPSS 0.04
CVE-2025-3444 MEDIUM
ManageEngine ServiceDesk Plus MSP and SupportCenter Plus < 14920 - Authenticated Local File Inclusion in Admin Help Card
May 22, 2025
CVSS 6.5
EPSS 0.01
CVE-2025-3834 HIGH
ManageEngine ADAudit Plus <= 8510 - Authenticated SQL Injection in OU History Report
May 14, 2025
CVSS 8.1
EPSS 0.04
CVE-2025-3833 HIGH
ManageEngine ADSelfService Plus <= 6513 - Authenticated SQL Injection in MFA Reports
May 14, 2025
CVSS 8.1
EPSS 0.10
CVE-2025-1724 HIGH
Zohocorp's ManageEngine Analytics Plus & Zoho Analytics <6130 - Pri...
Mar 17, 2025
CVSS 7.4
EPSS 0.01