zohocorp

559 tracked vulnerabilities.

CVE-2022-32551 HIGH
ManageEngine ServiceDesk Plus MSP < 10604 - Path Traversal via WEBINF/web.xml
Jul 02, 2022
CVSS 7.5
EPSS 0.03
CVE-2022-23050 HIGH
ManageEngine Applications Manager 15.0-15.5 - Authenticated DLL Hijacking via Upload Files Functionality
May 24, 2022
CVSS 7.2
EPSS 0.27
CVE-2022-28987 MEDIUM NUCLEI
Zoho ManageEngine ADSelfService Plus <6.2.02 - Info Disclosure
May 20, 2022
CVSS 5.3
EPSS 0.11
CVE-2022-29535 CRITICAL
Zoho ManageEngine OPManager through 125588 - SQL Injection via Default Reports
May 05, 2022
CVSS 9.8
EPSS 0.19
CVE-2022-29081 CRITICAL NUCLEI
Zoho ManageEngine <4302, <12007, <5401 - Auth Bypass
Apr 28, 2022
CVSS 9.8
EPSS 0.88
CVE-2022-29457 HIGH
Zohocorp ManageEngine ADAudit Plus - NTLM Hash Disclosure
Apr 18, 2022
CVSS 8.8
EPSS 0.08
CVE-2022-28810 MEDIUM KEV
ManageEngine ADSelfService Plus Custom Script Execution
Apr 18, 2022
CVSS 6.8
EPSS 0.90
CVE-2022-27908 HIGH
ManageEngine OpManager < 125588 - Authenticated SQL Injection in Inventory Reports Module
Apr 18, 2022
CVSS 8.8
EPSS 0.05
CVE-2022-26777 MEDIUM
Zoho ManageEngine Remote Access Plus <10.1.2137.15 - Info Disclosure
Apr 16, 2022
CVSS 5.3
EPSS 0.02
CVE-2022-26653 MEDIUM
Zoho ManageEngine Remote Access Plus <10.1.2137.15 - Info Disclosure
Apr 16, 2022
CVSS 5.3
EPSS 0.02
CVE-2022-24681 MEDIUM NUCLEI
Zoho ManageEngine ADSelfService Plus <6.12.1 - XSS
Apr 07, 2022
CVSS 6.1
EPSS 0.21
CVE-2022-28219 CRITICAL NUCLEI
ManageEngine ADAudit Plus CVE-2022-28219
Apr 05, 2022
CVSS 9.8
EPSS 0.94
CVE-2022-25373 MEDIUM
ManageEngine SupportCenter Plus < 11.0 - Stored Cross-Site Scripting in Request History
Apr 05, 2022
CVSS 5.4
EPSS 0.13
CVE-2022-25245 MEDIUM
Zoho ManageEngine ServiceDesk Plus < 13001 - Unauthenticated Information Disclosure
Apr 05, 2022
CVSS 5.3
EPSS 0.03
CVE-2022-24978 HIGH
ManageEngine ADAudit Plus < 7055 - Authenticated Privilege Escalation via Cleartext Password Exposure
Apr 05, 2022
CVSS 8.8
EPSS 0.00
CVE-2022-24447 MEDIUM
Zoho ManageEngine Key Manager Plus <6.2.00 - Info Disclosure
Mar 02, 2022
CVSS 6.5
EPSS 0.00
CVE-2022-24306 CRITICAL
Zoho ManageEngine SharePoint Manager Plus <4329 - Privilege Escalation
Mar 02, 2022
CVSS 9.8
EPSS 0.06
CVE-2022-24305 CRITICAL
Zoho ManageEngine SharePoint Manager Plus <4329 - Info Disclosure
Mar 02, 2022
CVSS 9.8
EPSS 0.13
CVE-2022-23779 MEDIUM NUCLEI
ManageEngine Desktop Central < 10.1.2137.8 - Unauthenticated Sensitive Information Exposure via HTTP Redirect
Mar 02, 2022
CVSS 5.3
EPSS 0.79
CVE-2022-24446 MEDIUM
Zoho ManageEngine Key Manager Plus <6.1.6 - Info Disclosure
Mar 01, 2022
CVSS 4.3
EPSS 0.02
CVE-2022-23863 MEDIUM
Zoho ManageEngine Desktop Central <10.1.2137.10 - Privilege Escalation
Jan 28, 2022
CVSS 6.5
EPSS 0.03
CVE-2021-46065 MEDIUM
Zoho ManageEngine ServiceDesk Plus 11.3 - XSS
Jan 27, 2022
CVSS 4.8
EPSS 0.20
CVE-2021-44757 CRITICAL
Zoho ManageEngine Desktop Central <10.1.2137.9 - Auth Bypass
Jan 18, 2022
CVSS 9.1
EPSS 0.41
CVE-2021-44652 HIGH
Zoho ManageEngine O365 Manager Plus < Build 4416 - Remote Code Execution via BCP File Overwrite in ChangeDBAPI
Jan 12, 2022
CVSS 7.8
EPSS 0.01
CVE-2021-44651 HIGH
ManageEngine CloudSecurityPlus < 4.1 - Remote Code Execution via updatePersonalizeSettings Component
Jan 12, 2022
CVSS 8.8
EPSS 0.08