zohocorp

559 tracked vulnerabilities.

CVE-2023-38331 MEDIUM
Zoho ManageEngine Support Center Plus <14001 - XSS
Jul 28, 2023
CVSS 5.4
EPSS 0.03
CVE-2023-37308 MEDIUM
ManageEngine ADAudit Plus < 7100 - Cross-Site Scripting via Username Field
Jul 07, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-34197 MEDIUM
Zoho ManageEngine <14202-14300 - Privilege Escalation
Jul 07, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-35786 MEDIUM
ManageEngine ADManager Plus < 7183 - Authenticated XML External Entity Injection
Jul 05, 2023
CVSS 4.9
EPSS 0.01
CVE-2023-35854 CRITICAL
ManageEngine ADSelfService Plus <= 6113 - Authentication Bypass via Session Token Theft
Jun 20, 2023
CVSS 9.8
EPSS 0.03
CVE-2023-31099 HIGH
Zoho ManageEngine OPManager <126323 - RCE
May 04, 2023
CVSS 8.8
EPSS 0.58
CVE-2023-2291 HIGH
ManageEngine Access Manager Plus, Password Manager Pro, and PAM360 - Use of Hard-coded Credentials in PostgreSQL Data
Apr 26, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-29443 MEDIUM
ManageEngine AssetExplorer < 6989 - XML External Entity Injection via Reports Integration API
Apr 26, 2023
CVSS 4.9
EPSS 0.06
CVE-2023-29442 MEDIUM
ManageEngine Applications Manager < 16400 - DOM-Based Cross-Site Scripting via proxy.html
Apr 26, 2023
CVSS 6.1
EPSS 0.05
CVE-2023-29084 HIGH NUCLEI
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
Apr 13, 2023
CVSS 7.2
EPSS 0.94
CVE-2023-28341 MEDIUM
Zoho ManageEngine Applications Manager <= 16340 - Unauthenticated Stored Cross-Site Scripting via Login Page
Apr 11, 2023
CVSS 6.1
EPSS 0.63
CVE-2023-28340 MEDIUM
Zoho ManageEngine Applications Manager <= 16320 - Authenticated XML External Entity Injection
Apr 11, 2023
CVSS 6.5
EPSS 0.08
CVE-2023-28342 HIGH
ManageEngine ADSelfService Plus < 6218 - Unauthenticated Denial of Service via Mobile App Authentication API
Apr 05, 2023
CVSS 7.5
EPSS 0.59
CVE-2023-26601 HIGH
ManageEngine Asset Explorer < 6.9 - Denial of Service
Mar 06, 2023
CVSS 7.5
EPSS 0.16
CVE-2023-26600 MEDIUM
ManageEngine - Privilege Escalation
Mar 06, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-0169 MEDIUM
Zoho Forms < 3.0.1 - Stored Cross-Site Scripting via Shortcode Attributes
Feb 13, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-23078 MEDIUM
Zoho ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Assets Comment Field
Feb 01, 2023
CVSS 6.1
EPSS 0.26
CVE-2023-23077 MEDIUM
ManageEngine ServiceDesk Plus 13 - Stored Cross-Site Scripting via Status Comment Field
Feb 01, 2023
CVSS 6.1
EPSS 0.26
CVE-2023-23076 CRITICAL
ManageEngine Support Center Plus 11 - OS Command Injection via Executor in Action
Feb 01, 2023
CVSS 9.8
EPSS 0.49
CVE-2023-23075 MEDIUM
Zoho ManageEngine AssetExplorer 6.9 - Stored Cross-Site Scripting via Credential Name
Feb 01, 2023
CVSS 6.1
EPSS 0.07
CVE-2023-23074 MEDIUM
ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Video Embedding in Language Component
Feb 01, 2023
CVSS 6.1
EPSS 0.71
CVE-2023-23073 MEDIUM
ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Purchase Order in Purchase Component
Feb 01, 2023
CVSS 6.1
EPSS 0.26
CVE-2023-22964 CRITICAL
ManageEngine ServiceDesk Plus MSP < 10611 and 13x < 13004 - Authentication Bypass via LDAP
Jan 20, 2023
CVSS 9.1
EPSS 0.01
CVE-2023-22624 HIGH
ManageEngine Exchange Reporter Plus < 5708 - XML External Entity Injection
Jan 17, 2023
CVSS 7.5
EPSS 0.05
CVE-2022-43473 MEDIUM
ManageEngine OpManager <12.6.168 - SSRF
Mar 30, 2023
CVSS 5.8
EPSS 0.36