Skip to main content

Vendor archive

zohocorp CVEs

Beta · best-effort

550 CVEs tagged to vendor zohocorp143 Critical, 196 High, 201 Medium, 10 Low, 0 Unrated.

CVE-2014-6038

Published Jan 13, 2020

Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7162

Published Dec 31, 2019

An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthenticated person to retrieve internal information from the syste…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18781

Published Dec 18, 2019

An open redirect vulnerability was discovered in Zoho ManageEngine ADSelfService Plus 5.x before 5809 that allows attackers to force users who click on a crafted link to be sent t…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19774

Published Dec 13, 2019

An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetails from hostdetails" at the /event/runquery.do endpoint, it…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-19649

Published Dec 11, 2019

Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServlet eventid parameter to the SyncEventServlet.java doGet fun…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18411

Published Nov 6, 2019

Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are attacked with this vulnerability will be forced to modify thei…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17602

Published Oct 15, 2019

An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, thi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-17112

Published Oct 9, 2019

An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15106

Published Aug 16, 2019

An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15105

Published Aug 16, 2019

An issue was discovered in Zoho ManageEngine Application Manager through 14.2. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid param…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15104

Published Aug 16, 2019

An issue was discovered in Zoho ManageEngine OpManager through 12.4x. There is a SQL Injection vulnerability in jsp/NewThresholdConfiguration.jsp via the resourceid parameter. The…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14693

Published Aug 8, 2019

Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attacker could exploit this vulnera…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 550 CVEsPage 15 of 22