Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44757 1 Zohocorp 2 Manageengine Desktop Central, Manageengine Desktop Central Managed Service Providers 2022-07-12 6.4 MEDIUM 9.1 CRITICAL
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
CVE-2021-37741 1 Zohocorp 1 Manageengine Admanager Plus 2022-07-12 6.5 MEDIUM 8.8 HIGH
ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
CVE-2021-37424 1 Zohocorp 1 Manageengine Admanager Plus 2022-07-12 7.5 HIGH 9.8 CRITICAL
ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
CVE-2021-37927 1 Zohocorp 1 Manageengine Admanager Plus 2022-07-12 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
CVE-2021-27214 1 Zohocorp 1 Manageengine Adselfservice Plus 2022-07-12 4.3 MEDIUM 6.1 MEDIUM
A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus through 6013 allows a remote unauthenticated attacker to perform blind HTTP requests or perform a Cross-site scripting (XSS) attack against the administrative interface via an HTTP request, a different vulnerability than CVE-2019-3905.
CVE-2021-41829 1 Zohocorp 1 Manageengine Remote Access Plus 2022-07-12 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
CVE-2021-37417 1 Zohocorp 1 Manageengine Adselfservice Plus 2022-07-12 5.0 MEDIUM 9.8 CRITICAL
Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
CVE-2021-20136 1 Zohocorp 1 Manageengine Log360 2022-07-12 7.5 HIGH 9.8 CRITICAL
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to change its backend database to an attacker-controlled database and to force Log360 to restart. An attacker can leverage this vulnerability to achieve remote code execution by replacing files executed by Log360 on startup.
CVE-2021-44515 1 Zohocorp 1 Manageengine Desktop Central 2022-07-12 10.0 HIGH 9.8 CRITICAL
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For Enterprise builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3. For MSP builds 10.1.2127.17 and earlier, upgrade to 10.1.2127.18. For MSP builds 10.1.2128.0 through 10.1.2137.2, upgrade to 10.1.2137.3.
CVE-2022-25373 1 Zohocorp 1 Manageengine Supportcenter Plus 2022-07-12 3.5 LOW 5.4 MEDIUM
Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history.
CVE-2020-11946 1 Zohocorp 1 Manageengine Opmanager 2022-07-10 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.
CVE-2020-10189 1 Zohocorp 1 Manageengine Desktop Central 2022-07-10 10.0 HIGH 9.8 CRITICAL
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
CVE-2022-28219 1 Zohocorp 1 Manageengine Adaudit Plus 2022-07-02 7.5 HIGH 9.8 CRITICAL
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
CVE-2022-28987 1 Zohocorp 1 Manageengine Adselfservice Plus 2022-07-02 5.0 MEDIUM 5.3 MEDIUM
Zoho ManageEngine ADSelfService Plus before 6202 allows attackers to perform username enumeration via a crafted POST request to /ServletAPI/accounts/login.
CVE-2022-24681 1 Zohocorp 1 Manageengine Adselfservice Plus 2022-05-17 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine ADSelfService Plus before 6121 allows XSS via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screen.
CVE-2022-29535 1 Zohocorp 1 Manageengine Opmanager 2022-05-17 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
CVE-2021-41080 1 Zohocorp 1 Manageengine Network Configuration Manager 2022-05-16 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Network Configuration Manager before ??125465 is vulnerable to SQL Injection in a hardware details search.
CVE-2021-41081 1 Zohocorp 1 Manageengine Network Configuration Manager 2022-05-16 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Network Configuration Manager before ??125465 is vulnerable to SQL Injection in a configuration search.
CVE-2022-29457 1 Zohocorp 4 Manageengine Adaudit Plus, Manageengine Admanager Plus, Manageengine Adselfservice Plus and 1 more 2022-05-11 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
CVE-2021-33911 1 Zohocorp 1 Manageengine Admanager Plus 2022-05-03 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
CVE-2020-15588 1 Zohocorp 1 Manageengine Desktop Central 2022-04-28 7.5 HIGH 9.8 CRITICAL
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue will occur only when untrusted communication is initiated with server. In cloud, Agent will always connect with trusted communication.
CVE-2021-42847 1 Zohocorp 1 Manageengine Adaudit Plus 2022-04-27 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
CVE-2021-43296 1 Zohocorp 1 Manageengine Supportcenter Plus 2022-04-27 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to an SSRF attack in ActionExecutor.
CVE-2021-43295 1 Zohocorp 1 Manageengine Supportcenter Plus 2022-04-27 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Accounts module.
CVE-2021-43294 1 Zohocorp 1 Manageengine Supportcenter Plus 2022-04-27 4.3 MEDIUM 6.1 MEDIUM
Zoho ManageEngine SupportCenter Plus before 11016 is vulnerable to Reflected XSS in the Products module.
CVE-2022-27908 1 Zohocorp 1 Manageengine Opmanager 2022-04-26 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.
CVE-2021-37419 1 Zohocorp 1 Manageengine Admanager Plus 2022-02-22 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
CVE-2021-46065 1 Zohocorp 1 Manageengine Servicedesk Plus 2022-02-02 3.5 LOW 4.8 MEDIUM
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
CVE-2021-44652 1 Zohocorp 1 Manageengine O365 Manager Plus 2022-01-25 6.8 MEDIUM 7.8 HIGH
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
CVE-2021-44651 1 Zohocorp 2 Log360, Manageengine Cloud Security Plus 2022-01-24 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
CVE-2021-44650 1 Zohocorp 1 Manageengine M365 Manager Plus 2022-01-24 6.5 MEDIUM 7.2 HIGH
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
CVE-2020-28679 1 Zohocorp 1 Manageengine Applications Manager 2022-01-19 6.5 MEDIUM 8.8 HIGH
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
CVE-2021-46165 1 Zohocorp 1 Manageengine Desktop Central 2022-01-14 4.6 MEDIUM 7.8 HIGH
Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but this file's path might not be properly defined.
CVE-2021-46164 1 Zohocorp 1 Manageengine Desktop Central 2022-01-14 6.5 MEDIUM 8.8 HIGH
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
CVE-2021-46166 1 Zohocorp 1 Manageengine Desktop Central 2022-01-13 4.0 MEDIUM 6.5 MEDIUM
Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the database by visiting the Reports page.
CVE-2021-20147 1 Zohocorp 1 Manageengine Adselfservice Plus 2022-01-13 5.0 MEDIUM 5.3 MEDIUM
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in the UMCP operation of the ChangePasswordAPI. This allows an unauthenticated remote attacker to determine whether a Windows domain user exists.
CVE-2021-44675 1 Zohocorp 1 Manageengine Servicedesk Plus Msp 2022-01-03 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine ServiceDesk Plus MSP before 10.5 Build 10534 is vulnerable to unauthenticated remote code execution due to a filter bypass in which authentication is not required.
CVE-2019-20474 1 Zohocorp 1 Manageengine Remote Access Plus 2022-01-01 4.0 MEDIUM 4.3 MEDIUM
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.
CVE-2021-37414 1 Zohocorp 1 Manageengine Desktop Central 2021-12-20 5.0 MEDIUM 7.5 HIGH
Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
CVE-2021-44514 1 Zohocorp 1 Manageengine Opmanager 2021-12-15 7.5 HIGH 9.8 CRITICAL
OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
CVE-2021-42099 1 Zohocorp 1 Manageengine M365 Manager Plus 2021-12-06 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
CVE-2020-15589 1 Zohocorp 2 Manageengine Desktop Central, Manageengine Remote Access Plus 2021-12-06 6.8 MEDIUM 8.1 HIGH
A design issue was discovered in GetInternetRequestHandle, InternetSendRequestEx and InternetSendRequestByBitrate in the client side of Zoho ManageEngine Desktop Central 10.0.552.W and Remote Access Plus before 10.1.2119.1. By exploiting this issue, an attacker-controlled server can force the client to skip TLS certificate validation, leading to a man-in-the-middle attack against HTTPS and unauthenticated remote code execution.
CVE-2021-43319 1 Zohocorp 1 Manageengine Network Configuration Manager 2021-12-03 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality.
CVE-2021-41833 1 Zohocorp 1 Manageengine Patch Connect Plus 2021-11-15 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
CVE-2020-24743 1 Zohocorp 1 Manageengine Applications Manager 2021-11-05 7.5 HIGH 9.8 CRITICAL
An issue was found in /showReports.do Zoho ManageEngine Applications Manager up to 14550, allows attackers to gain escalated privileges via the resourceid parameter.
CVE-2021-35512 1 Zohocorp 1 Manageengine Applications Manager 2021-10-28 6.4 MEDIUM 6.5 MEDIUM
An SSRF issue was discovered in Zoho ManageEngine Applications Manager build 15200.
CVE-2021-41075 1 Zohocorp 1 Manageengine Opmanager 2021-10-19 7.5 HIGH 9.8 CRITICAL
The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
CVE-2021-40493 1 Zohocorp 1 Manageengine Opmanager 2021-10-19 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.
CVE-2021-20130 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-19 6.5 MEDIUM 8.8 HIGH
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the PasswordExpiry interface.
CVE-2021-20131 1 Zohocorp 1 Manageengine Admanager Plus 2021-10-19 6.5 MEDIUM 8.8 HIGH
ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to improperly validated file uploads in the Personalization interface.