Vulnerabilities > Zohocorp > High

DATE CVE VULNERABILITY TITLE RISK
2023-04-13 CVE-2023-29084 Command Injection vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
network
low complexity
zohocorp CWE-77
7.2
2023-04-05 CVE-2023-28342 Unspecified vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
network
low complexity
zohocorp
7.5
2023-03-06 CVE-2023-26601 Resource Exhaustion vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
network
low complexity
zohocorp CWE-400
7.5
2023-02-25 CVE-2022-48362 Path Traversal vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet.
network
low complexity
zohocorp CWE-22
8.8
2023-01-17 CVE-2023-22624 XXE vulnerability in Zohocorp Manageengine Exchange Reporter Plus
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
network
low complexity
zohocorp CWE-611
7.5
2022-12-20 CVE-2022-47577 Unspecified vulnerability in Zohocorp Manageengine Device Control Plus 10.1.2228.15
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15.
local
low complexity
zohocorp
7.8
2022-12-20 CVE-2022-47578 Unspecified vulnerability in Zohocorp Manageengine Device Control Plus 10.1.2228.15
An issue was discovered in the endpoint protection agent in Zoho ManageEngine Device Control Plus 10.1.2228.15.
local
low complexity
zohocorp
7.8
2022-11-23 CVE-2022-40770 Command Injection vulnerability in Zohocorp Manageengine Servicedesk Plus
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection.
network
low complexity
zohocorp CWE-77
7.2
2022-11-18 CVE-2022-42904 Unspecified vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
network
low complexity
zohocorp
7.2
2022-11-12 CVE-2022-40773 Improper Input Validation vulnerability in Zohocorp products
Zoho ManageEngine ServiceDesk Plus MSP before 10609 and SupportCenter Plus before 11025 are vulnerable to privilege escalation.
network
low complexity
zohocorp CWE-20
8.8