zohocorp
559 tracked vulnerabilities.
CVE-2023-38331
MEDIUM
Zoho ManageEngine Support Center Plus <14001 - XSS
Jul 28, 2023
CVSS 5.4
EPSS 0.03
CVE-2023-37308
MEDIUM
ManageEngine ADAudit Plus < 7100 - Cross-Site Scripting via Username Field
Jul 07, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-34197
MEDIUM
Zoho ManageEngine <14202-14300 - Privilege Escalation
Jul 07, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-35786
MEDIUM
ManageEngine ADManager Plus < 7183 - Authenticated XML External Entity Injection
Jul 05, 2023
CVSS 4.9
EPSS 0.01
CVE-2023-35854
CRITICAL
ManageEngine ADSelfService Plus <= 6113 - Authentication Bypass via Session Token Theft
Jun 20, 2023
CVSS 9.8
EPSS 0.03
CVE-2023-31099
HIGH
Zoho ManageEngine OPManager <126323 - RCE
May 04, 2023
CVSS 8.8
EPSS 0.58
CVE-2023-2291
HIGH
ManageEngine Access Manager Plus, Password Manager Pro, and PAM360 - Use of Hard-coded Credentials in PostgreSQL Data
Apr 26, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-29443
MEDIUM
ManageEngine AssetExplorer < 6989 - XML External Entity Injection via Reports Integration API
Apr 26, 2023
CVSS 4.9
EPSS 0.06
CVE-2023-29442
MEDIUM
ManageEngine Applications Manager < 16400 - DOM-Based Cross-Site Scripting via proxy.html
Apr 26, 2023
CVSS 6.1
EPSS 0.05
CVE-2023-29084
HIGH
NUCLEI
ManageEngine ADManager Plus ChangePasswordAction Authenticated Command Injection
Apr 13, 2023
CVSS 7.2
EPSS 0.94
CVE-2023-28341
MEDIUM
Zoho ManageEngine Applications Manager <= 16340 - Unauthenticated Stored Cross-Site Scripting via Login Page
Apr 11, 2023
CVSS 6.1
EPSS 0.63
CVE-2023-28340
MEDIUM
Zoho ManageEngine Applications Manager <= 16320 - Authenticated XML External Entity Injection
Apr 11, 2023
CVSS 6.5
EPSS 0.08
CVE-2023-28342
HIGH
ManageEngine ADSelfService Plus < 6218 - Unauthenticated Denial of Service via Mobile App Authentication API
Apr 05, 2023
CVSS 7.5
EPSS 0.59
CVE-2023-26601
HIGH
ManageEngine Asset Explorer < 6.9 - Denial of Service
Mar 06, 2023
CVSS 7.5
EPSS 0.16
CVE-2023-26600
MEDIUM
ManageEngine - Privilege Escalation
Mar 06, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-0169
MEDIUM
Zoho Forms < 3.0.1 - Stored Cross-Site Scripting via Shortcode Attributes
Feb 13, 2023
CVSS 5.4
EPSS 0.01
CVE-2023-23078
MEDIUM
Zoho ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Assets Comment Field
Feb 01, 2023
CVSS 6.1
EPSS 0.26
CVE-2023-23077
MEDIUM
ManageEngine ServiceDesk Plus 13 - Stored Cross-Site Scripting via Status Comment Field
Feb 01, 2023
CVSS 6.1
EPSS 0.26
CVE-2023-23076
CRITICAL
ManageEngine Support Center Plus 11 - OS Command Injection via Executor in Action
Feb 01, 2023
CVSS 9.8
EPSS 0.49
CVE-2023-23075
MEDIUM
Zoho ManageEngine AssetExplorer 6.9 - Stored Cross-Site Scripting via Credential Name
Feb 01, 2023
CVSS 6.1
EPSS 0.07
CVE-2023-23074
MEDIUM
ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Video Embedding in Language Component
Feb 01, 2023
CVSS 6.1
EPSS 0.71
CVE-2023-23073
MEDIUM
ManageEngine ServiceDesk Plus 14 - Stored Cross-Site Scripting via Purchase Order in Purchase Component
Feb 01, 2023
CVSS 6.1
EPSS 0.26
CVE-2023-22964
CRITICAL
ManageEngine ServiceDesk Plus MSP < 10611 and 13x < 13004 - Authentication Bypass via LDAP
Jan 20, 2023
CVSS 9.1
EPSS 0.01
CVE-2023-22624
HIGH
ManageEngine Exchange Reporter Plus < 5708 - XML External Entity Injection
Jan 17, 2023
CVSS 7.5
EPSS 0.05
CVE-2022-43473
MEDIUM
ManageEngine OpManager <12.6.168 - SSRF
Mar 30, 2023
CVSS 5.8
EPSS 0.36
Products
manageengine_applications_manager 56
manageengine_opmanager 56
manageengine_admanager_plus 53
manageengine_adaudit_plus 52
manageengine_adselfservice_plus 51
manageengine_servicedesk_plus 50
manageengine_desktop_central 48
manageengine_supportcenter_plus 31
manageengine_exchange_reporter_plus 28
manageengine_netflow_analyzer 28
manageengine_assetexplorer 26
manageengine_servicedesk_plus_msp 26
manageengine_password_manager_pro 22
manageengine_eventlog_analyzer 19
manageengine_network_configuration_manager 14
manageengine_pam360 14
manageengine_remote_access_plus 14
manageengine_firewall_analyzer 12
manageengine_access_manager_plus 11
manageengine_it360 9
manageengine_log360 9
ManageEngine Exchange Reporter Plus 8
manageengine_endpoint_central 8
manageengine_oputils 8
manageengine_analytics_plus 7
manageengine_datasecurity_plus 6
manageengine_opmanager_msp 6
manageengine_opmanager_plus 6
manageengine_cloud_security_plus 5
manageengine_key_manager_plus 5
Quick Filters