zohocorp

559 tracked vulnerabilities.

CVE-2025-1723 HIGH
ManageEngine ADSelfService Plus <= 6510 - Authenticated Account Takeover via Session Mishandling
Mar 03, 2025
CVSS 8.1
EPSS 0.00
CVE-2024-50053 MEDIUM
Zohocorp ManageEngine <14920- SupportCentre Plus <14910 - XSS
Mar 21, 2025
CVSS 6.3
EPSS 0.00
CVE-2024-9097 LOW
ManageEngine Endpoint Central 11.3.2428.01-11.3.2428.26 - Insecure Direct Object Reference via Chat Username Change
Feb 05, 2025
CVSS 3.5
EPSS 0.00
CVE-2024-41140 HIGH
ManageEngine Applications Manager <= 174000 - Incorrect Authorization in Update User Function
Jan 29, 2025
CVSS 8.1
EPSS 0.00
CVE-2024-52323 HIGH
Zohocorp ManageEngine Analytics Plus <6100 - Info Disclosure
Nov 27, 2024
CVSS 8.1
EPSS 0.01
CVE-2024-49574 HIGH
Zohocorp ManageEngine ADAudit Plus <8123 - SQL Injection
Nov 18, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-10839 HIGH
ManageEngine SharePoint Manager Plus <= 4503 - Authenticated XML External Entity Injection in Management Option
Nov 08, 2024
CVSS 8.5
EPSS 0.00
CVE-2024-24409 HIGH
ManageEngine ADManager Plus <= 7203 - Privilege Escalation via Modify Computers Option
Nov 08, 2024
CVSS 8.8
EPSS 0.06
CVE-2024-10203 HIGH
Zohocorp Manageengine Endpoint Central < 11.3.2416.21 - Improper Privilege Management
Nov 07, 2024
CVSS 7.0
EPSS 0.00
CVE-2024-9459 HIGH
ManageEngine Exchange Reporter Plus <= 5718 - Authenticated SQL Injection in Reports Module
Nov 05, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-36485 HIGH
Zohocorp ManageEngine ADAudit Plus <8121 - SQL Injection
Nov 04, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-48878 HIGH
ManageEngine ADManager Plus <= 7241 - SQL Injection in Archived Audit Report
Nov 04, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-5608 HIGH
Zohocorp ManageEngine ADAudit Plus <8121 - SQL Injection
Oct 24, 2024
CVSS 8.3
EPSS 0.00
CVE-2024-38868 HIGH
ManageEngine Endpoint Central < 11.3.2400.15 - Incorrect Authorization during Device Isolation
Aug 30, 2024
CVSS 7.6
EPSS 0.00
CVE-2024-6204 HIGH
Zohocorp ManageEngine Exchange Reporter Plus <5715 - SQL Injection
Aug 30, 2024
CVSS 8.3
EPSS 0.00
CVE-2024-5546 HIGH
ManageEngine PAM360 < 7001 - Authenticated SQL Injection via Global Search Option
Aug 28, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-41150 MEDIUM
ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus < 14.7 - Stored XSS in Request Module
Aug 23, 2024
CVSS 6.3
EPSS 0.01
CVE-2024-38869 HIGH
ManageEngine Endpoint Central < 11.3.2416.04 & < 11.3.2400.25 - Incorrect Authorization
Aug 23, 2024
CVSS 8.3
EPSS 0.00
CVE-2024-5586 HIGH
ManageEngine ADAudit Plus < 8121 - Authenticated SQL Injection in Extranet Lockouts Report
Aug 23, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-5556 HIGH
ManageEngine ADAudit Plus < 8.0 - Authenticated SQL Injection in Reports Module
Aug 23, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-5490 HIGH
ManageEngine ADAudit Plus < 8.0 - Authenticated SQL Injection via Aggregate Reports Option
Aug 23, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-5467 HIGH
ManageEngine ADAudit Plus < 8121 - Authenticated SQL Injection in Account Lockout Report
Aug 23, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-5466 HIGH
ManageEngine OpManager and OpManager MSP < 12.7 - Authenticated Remote Code Execution via Deploy Agent Option
Aug 23, 2024
CVSS 8.8
EPSS 0.20
CVE-2024-36517 HIGH
Zohocorp ManageEngine ADAudit Plus <8000 - Authenticated SQL Injection
Aug 23, 2024
CVSS 8.3
EPSS 0.01
CVE-2024-36516 HIGH
Zohocorp ManageEngine ADAudit Plus <8000 - Authenticated SQL Injection
Aug 23, 2024
CVSS 8.3
EPSS 0.01