Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
Total 551 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-3324 1 Zohocorp 1 Manageengine Log360 2026-08-11 N/A 8.2 HIGH
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
CVE-2022-47966 1 Zohocorp 22 Manageengine Access Manager Plus, Manageengine Ad360, Manageengine Adaudit Plus and 19 more 2026-07-31 N/A 9.8 CRITICAL
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control Plus before 10.1.2220.18, Asset Explorer before 6983, Browser Security Plus before 11.1.2238.6, Device Control Plus before 10.1.2220.18, Endpoint Central before 10.1.2228.11, Endpoint Central MSP before 10.1.2228.11, Endpoint DLP before 10.1.2137.6, Key Manager Plus before 6401, OS Deployer before 1.1.2243.1, PAM 360 before 5713, Password Manager Pro before 12124, Patch Manager Plus before 10.1.2220.18, Remote Access Plus before 10.1.2228.11, Remote Monitoring and Management (RMM) before 10.1.41. ServiceDesk Plus before 14004, ServiceDesk Plus MSP before 13001, SupportCenter Plus before 11026, and Vulnerability Manager Plus before 10.1.2220.18. Exploitation is only possible if SAML SSO has ever been configured for a product (for some products, exploitation requires that SAML SSO is currently active).
CVE-2026-28754 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.
CVE-2026-4107 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.
CVE-2026-4108 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.
CVE-2026-3879 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.
CVE-2026-3880 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.
CVE-2026-28703 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.
CVE-2026-28756 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-24 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.
CVE-2026-27655 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-07-20 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.
CVE-2018-5353 1 Zohocorp 1 Manageengine Adselfservice Plus 2026-07-09 7.5 HIGH 9.8 CRITICAL
The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required
CVE-2025-9787 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.1 MEDIUM
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.
CVE-2025-9435 1 Zohocorp 1 Manageengine Admanager Plus 2026-06-17 N/A 5.5 MEDIUM
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
CVE-2025-9428 1 Zohocorp 1 Manageengine Analytics Plus 2026-06-17 N/A 8.3 HIGH
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
CVE-2025-7633 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-06-17 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.
CVE-2025-7632 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-06-17 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.
CVE-2025-7473 1 Zohocorp 1 Manageengine Endpoint Central 2026-06-17 N/A 5.2 MEDIUM
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
CVE-2025-7430 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-06-17 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.
CVE-2025-7429 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-06-17 N/A 7.3 HIGH
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.
CVE-2025-6239 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.5 MEDIUM
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.