Vulnerabilities
Vulnerable Software
Zohocorp:  Security Vulnerabilities
Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.
CVSS Score
9.8
EPSS Score
0.056
Published
2022-03-02
An issue was discovered in Zoho ManageEngine Key Manager Plus before 6200. A service exposed by the application allows a user, with the level Operator, to access stored SSL certificates and associated key pairs during export.
CVSS Score
6.5
EPSS Score
0.005
Published
2022-03-02
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
CVSS Score
4.3
EPSS Score
0.02
Published
2022-03-01
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
CVSS Score
6.5
EPSS Score
0.03
Published
2022-01-28
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
CVSS Score
4.8
EPSS Score
0.212
Published
2022-01-27
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
CVSS Score
9.1
EPSS Score
0.386
Published
2022-01-18
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
CVSS Score
8.8
EPSS Score
0.078
Published
2022-01-12
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
CVSS Score
7.8
EPSS Score
0.011
Published
2022-01-12
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
CVSS Score
7.2
EPSS Score
0.046
Published
2022-01-12
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.
CVSS Score
8.8
EPSS Score
0.047
Published
2022-01-10


Contact Us

Shodan ® - All rights reserved