Vulnerabilities
Vulnerable Software
Zohocorp:  Security Vulnerabilities
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.
CVSS Score
8.3
EPSS Score
0.007
Published
2024-02-02
ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in version 7271.
CVSS Score
8.3
EPSS Score
0.007
Published
2024-02-02
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.
CVSS Score
9.8
EPSS Score
0.086
Published
2024-02-02
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
CVSS Score
9.8
EPSS Score
0.086
Published
2024-02-02
Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
CVSS Score
2.7
EPSS Score
0.005
Published
2024-01-25
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
CVSS Score
5.4
EPSS Score
0.008
Published
2024-01-18
ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.
CVSS Score
8.8
EPSS Score
0.429
Published
2024-01-11
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
CVSS Score
9.1
EPSS Score
0.841
Published
2024-01-08
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zoho Forms Form plugin for WordPress – Zoho Forms allows Stored XSS.This issue affects Form plugin for WordPress – Zoho Forms: from n/a through 3.0.1.
CVSS Score
6.5
EPSS Score
0.003
Published
2023-12-29
Zoho ManageEngine RecoveryManager Plus before 6070 allows admin users to execute arbitrary commands via proxy settings.
CVSS Score
7.2
EPSS Score
0.631
Published
2023-11-22


Contact Us

Shodan ® - All rights reserved