Skip to main content

Vendor archive

zohocorp CVEs

Beta · best-effort

551 CVEs tagged to vendor zohocorp143 Critical, 197 High, 201 Medium, 10 Low, 0 Unrated.

CVE-2023-47211

Published Jan 8, 2024

A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation.…

CVSS 9.1 · Critical

CVE-2023-50891

Published Dec 29, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issu…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-4769

Published Nov 3, 2023

A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authentic…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4768

Published Nov 3, 2023

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP he…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4767

Published Nov 3, 2023

A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP he…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35719

Published Sep 6, 2023

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31492

Published Aug 17, 2023

Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27449

Published Aug 11, 2023

Cross Site Scripting (XSS) vulnerability in Query Report feature in Zoho ManageEngine Password Manager Pro version 11001, allows remote attackers to execute arbitrary code and ste…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38332

Published Aug 4, 2023

Zoho ManageEngine ADManager Plus through 7201 allow authenticated users to take over another user's account via sensitive information disclosure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35854

Published Jun 20, 2023

Zoho ManageEngine ADSelfService Plus through 6113 has an authentication bypass that can be exploited to steal the domain controller session token for identity spoofing, thereby ac…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-31099

Published May 4, 2023

Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 101-125 of 551 CVEsPage 5 of 23