Show filters
506 Total Results
Displaying 151-160 of 506
Sort by:
Attacker Value
Unknown

CVE-2022-24305

Disclosure Date: March 02, 2022 (last updated October 07, 2023)
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.
Attacker Value
Unknown

CVE-2022-23779

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Zoho ManageEngine Desktop Central before 10.1.2137.8 exposes the installed server name to anyone. The internal hostname can be discovered by reading HTTP redirect responses.
Attacker Value
Unknown

CVE-2022-24446

Disclosure Date: March 01, 2022 (last updated October 07, 2023)
An issue was discovered in Zoho ManageEngine Key Manager Plus 6.1.6. A user, with the level Operator, can see all SSH servers (and user information) even if no SSH server or user is associated to the operator.
Attacker Value
Unknown

CVE-2022-23863

Disclosure Date: January 28, 2022 (last updated October 07, 2023)
Zoho ManageEngine Desktop Central before 10.1.2137.10 allows an authenticated user to change any user's login password.
Attacker Value
Unknown

CVE-2021-46065

Disclosure Date: January 27, 2022 (last updated February 23, 2025)
A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 11306 allows an attackers to inject arbitrary JavaScript code.
Attacker Value
Unknown

CVE-2021-44757

Disclosure Date: January 18, 2022 (last updated October 07, 2023)
Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypass authentication, and read sensitive information or upload an arbitrary ZIP archive to the server.
Attacker Value
Unknown

CVE-2021-44652

Disclosure Date: January 12, 2022 (last updated October 07, 2023)
Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the ChangeDBAPI component.
Attacker Value
Unknown

CVE-2021-44651

Disclosure Date: January 12, 2022 (last updated February 23, 2025)
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings component due to an improper security patch for CVE-2021-40175.
Attacker Value
Unknown

CVE-2021-44650

Disclosure Date: January 12, 2022 (last updated October 07, 2023)
Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings through the Admin ProxySettings and Tenant ProxySettings components.
Attacker Value
Unknown

CVE-2020-28679

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
A vulnerability in the showReports module of Zoho ManageEngine Applications Manager before build 14550 allows authenticated attackers to execute a SQL injection via a crafted request.