Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Zohocorp Subscribe
Total 418 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-48362 1 Zohocorp 1 Manageengine Desktop Central 2023-03-14 N/A 8.8 HIGH
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting CVE-2021-44515.)
CVE-2023-26600 1 Zohocorp 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more 2023-03-13 N/A 6.5 MEDIUM
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
CVE-2023-26601 1 Zohocorp 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more 2023-03-13 N/A 7.5 HIGH
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
CVE-2019-12252 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-03-01 4.0 MEDIUM 6.5 MEDIUM
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post by appending its number to the SDNotify.do?notifyModule=Solution&mode=E-Mail&notifyTo=SOLFORWARD&id= substring.
CVE-2019-12597 1 Zohocorp 1 Manageengine Assetexplorer 2023-03-01 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via ResourcesAttachments.jsp with the parameter pageName.
CVE-2019-12595 1 Zohocorp 1 Manageengine Assetexplorer 2023-03-01 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the RCSettings.do rdsName parameter.
CVE-2019-12596 1 Zohocorp 1 Manageengine Assetexplorer 2023-03-01 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via SoftwareListView.do with the parameter swType or swComplianceType.
CVE-2019-12537 1 Zohocorp 1 Manageengine Assetexplorer 2023-03-01 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Zoho ManageEngine AssetExplorer. There is XSS via the SearchN.do search field.
CVE-2023-23076 1 Zohocorp 1 Manageengine Supportcenter Plus 2023-02-22 N/A 9.8 CRITICAL
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
CVE-2023-23077 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-02-22 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
CVE-2023-23078 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-02-22 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
CVE-2021-41081 1 Zohocorp 1 Manageengine Network Configuration Manager 2023-02-22 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Network Configuration Manager before ??125465 is vulnerable to SQL Injection in a configuration search.
CVE-2021-41080 1 Zohocorp 1 Manageengine Network Configuration Manager 2023-02-22 7.5 HIGH 9.8 CRITICAL
Zoho ManageEngine Network Configuration Manager before ??125465 is vulnerable to SQL Injection in a hardware details search.
CVE-2023-0169 1 Zohocorp 1 Zoho Forms 2023-02-15 N/A 5.4 MEDIUM
The Zoho Forms WordPress plugin before 3.0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2019-19774 1 Zohocorp 1 Manageengine Eventlog Analyzer 2023-02-14 4.0 MEDIUM 8.8 HIGH
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it is possible to bypass the security restrictions that prevent even administrative users from viewing credential data stored in the database, and recover the MD5 hashes of the accounts used to authenticate the ManageEngine platform to the managed machines on the network (most often administrative accounts). Specifically, this bypasses these restrictions: a query cannot mention password, and a query result cannot have a password column.
CVE-2023-23073 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-02-14 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
CVE-2023-23074 1 Zohocorp 1 Manageengine Servicedesk Plus 2023-02-14 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
CVE-2022-47966 1 Zohocorp 23 Application Control Plus, Manageengine Access Manager Plus, Manageengine Ad360 and 20 more 2023-02-09 N/A 9.8 CRITICAL
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections.
CVE-2023-23075 1 Zohocorp 1 Manageengine Assetexplorer 2023-02-08 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
CVE-2019-19034 1 Zohocorp 1 Manageengine Assetexplorer 2023-02-03 6.5 MEDIUM 7.2 HIGH
Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for SCCM. This allows an attacker to execute arbitrary commands on the AssetExplorer Server with NT AUTHORITY/SYSTEM privileges.