zohocorp

559 tracked vulnerabilities.

CVE-2021-44650 HIGH
Zoho ManageEngine M365 Manager Plus <Build 4419 - Command Injection
Jan 12, 2022
CVSS 7.2
EPSS 0.05
CVE-2021-46166 MEDIUM
Zoho ManageEngine Desktop Central <10.0.662 - Info Disclosure
Jan 10, 2022
CVSS 6.5
EPSS 0.00
CVE-2021-46165 HIGH
Zoho ManageEngine Desktop Central <10.0.662 - Code Injection
Jan 10, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-46164 HIGH
Zoho ManageEngine Desktop Central <10.0.662 - RCE
Jan 10, 2022
CVSS 8.8
EPSS 0.10
CVE-2021-20148 MEDIUM
ManageEngine ADSelfService Plus <6116 - Info Disclosure
Jan 03, 2022
CVSS 4.3
EPSS 0.00
CVE-2021-20147 MEDIUM
ManageEngine ADSelfService Plus < 6.0 - Unauthenticated User Enumeration via UMCP ChangePasswordAPI
Jan 03, 2022
CVSS 5.3
EPSS 0.18
CVE-2021-44526 CRITICAL
Zoho ManageEngine ServiceDesk Plus < 12003 - Authentication Bypass
Dec 23, 2021
CVSS 9.8
EPSS 0.04
CVE-2021-44525 CRITICAL
ManageEngine PAM360 < 5303 - Unauthenticated Authentication Bypass via Filter Bypass
Dec 20, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-44676 CRITICAL
ManageEngine Access Manager Plus < 4203 - Authentication Bypass
Dec 20, 2021
CVSS 9.8
EPSS 0.08
CVE-2021-44675 CRITICAL
ManageEngine ServiceDesk Plus MSP < 10.5 - Unauthenticated Remote Code Execution via Authentication Bypass
Dec 20, 2021
CVSS 9.8
EPSS 0.03
CVE-2021-44515 CRITICAL KEVNUCLEI
ManageEngine Desktop Central < 10.1.2127.18 - Authentication Bypass leading to Remote Code Execution
Dec 12, 2021
CVSS 9.8
EPSS 0.94
CVE-2021-44514 CRITICAL
Zoho ManageEngine OpManager < 125490 - Improper Authentication in OpUtils Audit Directories
Dec 09, 2021
CVSS 9.8
EPSS 0.05
CVE-2021-43319 CRITICAL
Zoho ManageEngine Network Config Mgr <125488 - Command Injection
Nov 30, 2021
CVSS 9.8
EPSS 0.74
CVE-2021-43296 HIGH
Zoho ManageEngine SupportCenter Plus <11016 - SSRF
Nov 30, 2021
CVSS 7.5
EPSS 0.08
CVE-2021-43295 MEDIUM
Zoho ManageEngine SupportCenter Plus <11016 - XSS
Nov 30, 2021
CVSS 6.1
EPSS 0.05
CVE-2021-43294 MEDIUM
Zoho ManageEngine SupportCenter Plus <11016 - XSS
Nov 30, 2021
CVSS 6.1
EPSS 0.05
CVE-2021-42099 CRITICAL
Zoho ManageEngine M365 Manager Plus < 4421 - Remote Code Execution via Unrestricted File Upload
Nov 30, 2021
CVSS 9.8
EPSS 0.22
CVE-2021-44077 CRITICAL KEVNUCLEI
ManageEngine ServiceDesk Plus CVE-2021-44077
Nov 29, 2021
CVSS 9.8
EPSS 0.94
CVE-2021-42955 HIGH
Zoho Remote Access Plus Server <10.1.2132 - Privilege Escalation
Nov 17, 2021
CVSS 7.3
EPSS 0.00
CVE-2021-42954 HIGH
Zoho Remote Access Plus Server - Privilege Escalation
Nov 17, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-42847 CRITICAL
ManageEngine ADAudit Plus Authenticated File Write RCE
Nov 11, 2021
CVSS 9.8
EPSS 0.83
CVE-2021-42002 CRITICAL
Zoho ManageEngine ADManager Plus < 7115 - Remote Code Execution via File Upload Filter Bypass
Nov 11, 2021
CVSS 9.8
EPSS 0.09
CVE-2021-41833 CRITICAL
Zoho ManageEngine Patch Connect Plus < 90099 - Unauthenticated Remote Code Execution via Unrestricted File Upload
Nov 11, 2021
CVSS 9.8
EPSS 0.27
CVE-2021-41081 CRITICAL
Zoho ManageEngine Network Config Mgr <125465 - SQL Injection
Nov 11, 2021
CVSS 9.8
EPSS 0.27
CVE-2021-41080 CRITICAL
Zoho ManageEngine Network Config Mgr <125465 - SQL Injection
Nov 11, 2021
CVSS 9.8
EPSS 0.15