Vulnerabilities (CVE)

Filtered by vendor Zohocorp Subscribe
Total 550 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-31492 1 Zohocorp 1 Manageengine Admanager Plus 2026-06-17 N/A 6.5 MEDIUM
Zoho ManageEngine ADManager Plus version 7182 and prior disclosed the default passwords for the account restoration of unauthorized domains to the authenticated users.
CVE-2023-31099 1 Zohocorp 1 Manageengine Opmanager 2026-06-17 N/A 8.8 HIGH
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
CVE-2023-2291 1 Zohocorp 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro 2026-06-17 N/A 7.8 HIGH
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to an Administrative user.
CVE-2023-29505 1 Zohocorp 1 Manageengine Network Configuration Manager 2026-06-17 N/A 4.3 MEDIUM
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
CVE-2023-29443 1 Zohocorp 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more 2026-06-17 N/A 4.9 MEDIUM
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
CVE-2023-29442 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.1 MEDIUM
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
CVE-2023-29084 1 Zohocorp 1 Manageengine Admanager Plus 2026-06-17 N/A 7.2 HIGH
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
CVE-2023-28342 1 Zohocorp 1 Manageengine Adselfservice Plus 2026-06-17 N/A 7.5 HIGH
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
CVE-2023-28341 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.1 MEDIUM
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
CVE-2023-28340 1 Zohocorp 1 Manageengine Applications Manager 2026-06-17 N/A 6.5 MEDIUM
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
CVE-2023-26601 1 Zohocorp 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more 2026-06-17 N/A 7.5 HIGH
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
CVE-2023-26600 1 Zohocorp 4 Manageengine Assetexplorer, Manageengine Servicedesk Plus, Manageengine Servicedesk Plus Msp and 1 more 2026-06-17 N/A 6.5 MEDIUM
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
CVE-2023-23078 1 Zohocorp 1 Manageengine Servicedesk Plus 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via the comment field when changing the credentials in the Assets.
CVE-2023-23077 1 Zohocorp 1 Manageengine Servicedesk Plus 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 13 via the comment field when adding a new status comment.
CVE-2023-23076 1 Zohocorp 1 Manageengine Supportcenter Plus 2026-06-17 N/A 9.8 CRITICAL
OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules.
CVE-2023-23075 1 Zohocorp 1 Manageengine Assetexplorer 2026-06-17 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in Zoho Asset Explorer 6.9 via the credential name when creating a new Assets Workstation.
CVE-2023-23074 1 Zohocorp 1 Manageengine Servicedesk Plus 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via embedding videos in the language component.
CVE-2023-23073 1 Zohocorp 1 Manageengine Servicedesk Plus 2026-06-17 N/A 6.1 MEDIUM
Cross site scripting (XSS) vulnerability in Zoho ManageEngine ServiceDesk Plus 14 via PO in the purchase component.
CVE-2023-22964 1 Zohocorp 1 Manageengine Servicedesk Plus Msp 2026-06-17 N/A 9.1 CRITICAL
Zoho ManageEngine ServiceDesk Plus MSP before 10611, and 13x before 13004, is vulnerable to authentication bypass when LDAP authentication is enabled.
CVE-2023-22624 1 Zohocorp 1 Manageengine Exchange Reporter Plus 2026-06-17 N/A 7.5 HIGH
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.