Vulnerabilities > Zohocorp > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-02 CVE-2022-23779 Information Exposure vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone.
network
low complexity
zohocorp CWE-200
5.0
2022-03-02 CVE-2022-24447 Unspecified vulnerability in Zohocorp Manageengine KEY Manager Plus 5.6/6.0/6.1
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200.
network
low complexity
zohocorp
6.5
2022-03-01 CVE-2022-24446 Unspecified vulnerability in Zohocorp Manageengine KEY Manager Plus 6.1.6
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6.
network
low complexity
zohocorp
4.3
2022-01-28 CVE-2022-23863 Unspecified vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
network
low complexity
zohocorp
6.5
2022-01-18 CVE-2021-44757 Unspecified vulnerability in Zohocorp products
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
network
low complexity
zohocorp
6.4
2022-01-12 CVE-2021-44651 Unrestricted Upload of File with Dangerous Type vulnerability in Zohocorp Log360 and Manageengine Cloud Security Plus
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
network
low complexity
zohocorp CWE-434
6.5
2022-01-12 CVE-2021-44652 Unspecified vulnerability in Zohocorp Manageengine O365 Manager Plus
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
network
zohocorp
6.8
2022-01-12 CVE-2021-44650 Unspecified vulnerability in Zohocorp Manageengine M365 Manager Plus 4.4
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
network
low complexity
zohocorp
6.5
2022-01-10 CVE-2020-28679 SQL Injection vulnerability in Zohocorp Manageengine Applications Manager
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
network
low complexity
zohocorp CWE-89
6.5
2022-01-10 CVE-2021-46164 Unspecified vulnerability in Zohocorp Manageengine Desktop Central
Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete access to the Reports module.
network
low complexity
zohocorp
6.5