Skip to main content

Vendor archive

zohocorp CVEs

Beta · best-effort

550 CVEs tagged to vendor zohocorp143 Critical, 196 High, 201 Medium, 10 Low, 0 Unrated.

CVE-2020-12116

Published May 7, 2020

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a craft…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10859

Published May 5, 2020

Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API r…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11527

Published Apr 4, 2020

In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8838

Published Mar 23, 2020

An issue was discovered in Zoho ManageEngine AssetExplorer 6.5. During an upgrade of the Windows agent, it does not validate the source and binary downloaded. This allows an attac…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19034

Published Mar 23, 2020

Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username when dynamically generating a command to schedule scans for…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9347

Published Mar 16, 2020

Zoho ManageEngine Password Manager Pro through 10.x has a CSV Excel Macro Injection vulnerability via a crafted name that is mishandled by the Export Passwords feature. NOTE: the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10541

Published Mar 13, 2020

Zoho ManageEngine OpManager before 12.4.179 allows remote code execution via a specially crafted Mail Server Settings v1 API request. This was fixed in 12.5.108.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1159

Published Mar 9, 2020

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulne…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10189

Published Mar 6, 2020

Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is rela…

CVSS 9.8 · Critical
evidence mentions
20
Buzz score
74.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-20474

Published Feb 17, 2020

An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user wit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8422

Published Jan 31, 2020

An authorization issue was discovered in the Credential Manager feature in Zoho ManageEngine Remote Access Plus before 10.0.450. A user with the Guest role can extract the collect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7390

Published Jan 27, 2020

Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 326-350 of 550 CVEsPage 14 of 22