zohocorp

559 tracked vulnerabilities.

CVE-2023-49333 HIGH
Zoho ManageEngine ADAudit Plus <7271 - SQL Injection
May 20, 2024
CVSS 8.3
EPSS 0.01
CVE-2023-49332 HIGH
Zoho ManageEngine ADAudit Plus <7271 - SQL Injection
May 20, 2024
CVSS 8.3
EPSS 0.01
CVE-2023-49331 HIGH
Zoho ManageEngine ADAudit Plus <7271 - SQL Injection
May 20, 2024
CVSS 8.3
EPSS 0.01
CVE-2023-49330 HIGH
Zoho ManageEngine ADAudit Plus <7271 - SQL Injection
May 20, 2024
CVSS 8.3
EPSS 0.01
CVE-2023-48793 CRITICAL
Zoho ManageEngine ADAudit Plus <7250 - SQL Injection
Feb 02, 2024
CVSS 9.8
EPSS 0.09
CVE-2023-48792 CRITICAL
Zoho ManageEngine ADAudit Plus <7250 - SQL Injection
Feb 02, 2024
CVSS 9.8
EPSS 0.09
CVE-2023-50785 LOW
ManageEngine ADAudit Plus < 7270 - Authenticated Path Traversal
Jan 25, 2024
CVSS 2.7
EPSS 0.01
CVE-2023-49943 MEDIUM
ManageEngine ServiceDesk Plus MSP < 14504 - Stored Cross-Site Scripting via Task Name in Timesheet
Jan 18, 2024
CVSS 5.4
EPSS 0.01
CVE-2023-47211 CRITICAL NUCLEI
ManageEngine Firewall Analyzer < 12.7 - Path Traversal and Arbitrary File Write via MIB Upload
Jan 08, 2024
CVSS 9.1
EPSS 0.76
CVE-2023-50891 MEDIUM
Zoho Forms < 3.0.1 - Stored Cross-Site Scripting
Dec 29, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-48646 HIGH
Zoho ManageEngine RecoveryManager Plus <6070 - Command Injection
Nov 22, 2023
CVSS 7.2
EPSS 0.59
CVE-2023-6105 MEDIUM
ManageEngine Products - Unauthorized Encryption Key Exposure
Nov 15, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-4769 MEDIUM
ManageEngine Desktop Central 9.1.0 - Authenticated Server-Side Request Forgery via /smtpConfig.do
Nov 03, 2023
CVSS 6.6
EPSS 0.00
CVE-2023-4768 MEDIUM
ManageEngine Desktop Central <9.1.0 - CRLF Injection
Nov 03, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-4767 MEDIUM
ManageEngine Desktop Central <9.1.0 - CRLF Injection
Nov 03, 2023
CVSS 6.1
EPSS 0.01
CVE-2023-41904 MEDIUM
ManageEngine ADManager Plus < 7203 - Two-Factor Authentication Bypass via REST API
Sep 27, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-38743 HIGH
Zoho ManageEngine ADManager Plus <Build 7200 - Command Injection
Sep 11, 2023
CVSS 7.2
EPSS 0.21
CVE-2023-35719 MEDIUM
ManageEngine ADSelfService Plus - Unauthenticated Authentication Bypass via GINA Client Password Reset Portal
Sep 06, 2023
CVSS 6.8
EPSS 0.00
CVE-2023-39912 MEDIUM
ManageEngine ADManager Plus < 7203 - Authenticated Arbitrary File Read via Help Desk Technician Role
Aug 31, 2023
CVSS 4.9
EPSS 0.01
CVE-2023-35785 HIGH
ManageEngine Active Directory 360 <= 4315 - Two-Factor Authentication Bypass via TOTP Authenticators
Aug 28, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-31492 MEDIUM
Zoho ManageEngine ADManager Plus <7182 - Info Disclosure
Aug 17, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-38333 MEDIUM
Zoho ManageEngine Applications Manager <16530 - XSS
Aug 10, 2023
CVSS 6.1
EPSS 0.06
CVE-2023-32783 HIGH
Zoho ManageEngine ADAudit Plus 7.1.1 - Audit Detection Bypass via User Account Name Suffix
Aug 07, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-38332 MEDIUM
Zoho ManageEngine ADManager Plus <7201 - Info Disclosure
Aug 04, 2023
CVSS 6.5
EPSS 0.02
CVE-2023-29505 MEDIUM
ManageEngine Network Configuration Manager 12.6.165 - Cross-site WebSocket Hijacking via WebSocket Endpoint
Aug 04, 2023
CVSS 4.3
EPSS 0.01