Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

Zoho

Vulnerabilities in Zoho's ManageEngine suite — ADSelfService Plus, ADAudit Plus, ServiceDesk Plus, and adjacent identity and IT-management tools — where authentication bypasses and unauthenticated RCEs draw APT groups and ransomware operators as quickly as CVEs are published.

9 CVEs0 articlesRSS
CVEs
CVE-2022-28810
[ MEDIUM ]CVSS 6.8EPSS 71.0%kev

Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

Zoho / ManageEngine
CVE-2022-47966
[ CRITICAL ]CVSS 9.8EPSS 99.8%kev

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

Zoho / ManageEngine
CVE-2022-35405
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

Zoho / ManageEngine
CVE-2021-44515
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

Zoho Desktop Central Authentication Bypass Vulnerability

Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.

Zoho / Desktop Central
CVE-2021-37415
[ CRITICAL ]CVSS 9.8EPSS 99.8%kev

Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

Zoho / ManageEngine ServiceDesk Plus (SDP)
CVE-2021-44077
[ CRITICAL ]CVSS 9.8EPSS 93.3%kev

Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

Zoho / ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus
CVE-2019-8394
[ MEDIUM ]CVSS 6.5EPSS 63.3%kev

Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

Zoho / ManageEngine
CVE-2020-10189
[ CRITICAL ]CVSS 9.8EPSS 99.9%kev

Zoho ManageEngine Desktop Central File Upload Vulnerability

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

Zoho / ManageEngine
CVE-2021-40539
[ CRITICAL ]CVSS 9.8EPSS 99.0%kev

Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

Zoho / ManageEngine