Vulnerabilities > Zohocorp

DATE CVE VULNERABILITY TITLE RISK
2021-10-07 CVE-2021-37926 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37928 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37929 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37930 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-07 CVE-2021-37931 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.
network
low complexity
zohocorp CWE-434
critical
9.8
2021-10-05 CVE-2021-33849 Cross-site Scripting vulnerability in Zohocorp Zoho CRM Lead Magnet 1.7.2.4
A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user’s browser while the browser is connected to a trusted website.
network
low complexity
zohocorp CWE-79
5.4
2021-09-30 CVE-2021-41288 SQL Injection vulnerability in Zohocorp Manageengine Opmanager
Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
network
low complexity
zohocorp CWE-89
critical
9.8
2021-09-30 CVE-2021-41827 Use of Hard-coded Credentials vulnerability in Zohocorp Manageengine Remote Access Plus
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access.
network
low complexity
zohocorp CWE-798
7.5
2021-09-30 CVE-2021-41828 Use of Hard-coded Credentials vulnerability in Zohocorp Manageengine Remote Access Plus
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
network
low complexity
zohocorp CWE-798
7.5
2021-09-30 CVE-2021-41829 Use of Insufficiently Random Values vulnerability in Zohocorp Manageengine Remote Access Plus
Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.
network
low complexity
zohocorp CWE-330
7.5