zohocorp
- Products in analyzed data
- 4
- Catalog vulnerabilities
- 573
Severity across 2 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 2 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 573 vulnerability records associated with zohocorp.
Among the 2 records analyzed by CyStack, 2 are High or Critical and 0 appear in the CISA KEV catalog for priority remediation.
The list below is based on vulnerabilities that have been viewed and analyzed; it does not represent the complete global vulnerability corpus. Use the product filter to narrow the scope.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-77697Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Endpoint Central | Published09/07/2026 | SeverityMedium |
CVE-2026-85640Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Endpoint Central | Published09/07/2026 | SeverityMedium |
CVE-2026-77699Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Endpoint Central | Published09/07/2026 | SeverityMedium |
CVE-2026-77698Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Endpoint Central | Published09/07/2026 | SeverityMedium |
CVE-2026-14828CVE-2026-14828 | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Password Manager Pro | Published09/02/2026 | SeverityHigh |
CVE-2026-12263Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Password Manager Pro | Published08/13/2026 | SeverityHigh |
CVE-2026-11840SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Password Manager Pro | Published08/13/2026 | SeverityHigh |
CVE-2026-12571Authentication Bypass Leading to Account Takeover | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_ddi_central | Published08/11/2026 | SeverityCritical |
CVE-2026-16053Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_m365_manager_plus | Published08/11/2026 | SeverityHigh |
CVE-2026-6516Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_adaudit_plus | Published07/23/2026 | SeverityCritical |
CVE-2026-3183Multi Factor Auth Bypass | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_adselfservice_plus | Published07/21/2026 | SeverityHigh |
CVE-2026-3182Sensitive Data Exposure | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Endpoint Central | Published07/21/2026 | SeverityMedium |
CVE-2026-11374Account Takeover via Predictable SSO Ticket Generation | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_adselfservice_plus | Published06/23/2026 | SeverityCritical |
CVE-2026-8174Cross-site Request Forgery | Exploitation statusNot known exploited | FixYes | Affected productZoho Mail wordpress plugin | Published05/26/2026 | SeverityMedium |
CVE-2026-2740Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_adselfservice_plus | Published05/21/2026 | SeverityHigh |
CVE-2026-3324Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Log360 | Published04/16/2026 | SeverityHigh |
CVE-2026-5785SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productManageEngine PAM360 | Published04/16/2026 | SeverityHigh |
CVE-2026-27655Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-4108Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-4107Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-3880Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-3879Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-28703Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-28756Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-28754Stored XSS Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published04/03/2026 | SeverityHigh |
CVE-2026-1367SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_adselfservice_plus | Published02/23/2026 | SeverityHigh |
CVE-2025-9226Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine OpManager | Published01/30/2026 | SeverityMedium |
CVE-2025-11669Broken Access Control | Exploitation statusNot known exploited | FixYes | Affected productManageEngine PAM360 | Published01/13/2026 | SeverityHigh |
CVE-2025-11250Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected productmanageengine_adselfservice_plus | Published01/13/2026 | SeverityCritical |
CVE-2025-9435Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productManageEngine ADManager Plus | Published01/13/2026 | SeverityMedium |
CVE-2025-9787Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Applications Manager | Published12/18/2025 | SeverityMedium |
CVE-2025-11670NTLM Hash Exposure Vulnerability | Exploitation statusNot known exploited | FixYes | Affected productManageEngine ADManager Plus | Published12/15/2025 | SeverityMedium |
CVE-2025-9227Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine OpManager | Published11/11/2025 | SeverityMedium |
CVE-2025-9223Command Injection | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Applications Manager | Published11/11/2025 | SeverityHigh |
CVE-2025-8324SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Analytics Plus | Published11/11/2025 | SeverityCritical |
CVE-2025-7633Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published11/11/2025 | SeverityHigh |
CVE-2025-7632Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published11/11/2025 | SeverityHigh |
CVE-2025-7430Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published11/11/2025 | SeverityHigh |
CVE-2025-7429Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published11/11/2025 | SeverityHigh |
CVE-2025-5347Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published10/30/2025 | SeverityMedium |
CVE-2025-5343Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published10/30/2025 | SeverityMedium |
CVE-2025-5342Denial of Service (DoS) | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Exchange Reporter Plus | Published10/30/2025 | SeverityMedium |
CVE-2025-11248Sensitive Information Logged | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Endpoint Central | Published10/27/2025 | SeverityLow |
CVE-2025-6239Information disclosure | Exploitation statusNot known exploited | FixYes | Affected productManageEngine Applications Manager | Published10/21/2025 | SeverityMedium |
CVE-2025-10020Command Injection | Exploitation statusNot known exploited | FixYes | Affected productManageEngine ADManager Plus | Published10/21/2025 | SeverityHigh |
CVE-2025-9428SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productAnalytics Plus | Published10/21/2025 | SeverityHigh |
CVE-2025-7473XML Injection | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published10/21/2025 | SeverityMedium |
CVE-2025-5496Arbitrary File Deletion | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published10/21/2025 | SeverityLow |
CVE-2025-5494Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published09/25/2025 | SeverityLow |
CVE-2025-27930Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productApplications Manager | Published07/23/2025 | SeverityMedium |
CVE-2025-5966Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published06/26/2025 | SeverityHigh |
CVE-2025-5366Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published06/26/2025 | SeverityHigh |
CVE-2025-41444SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published06/09/2025 | SeverityHigh |
CVE-2025-36528SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published06/09/2025 | SeverityHigh |
CVE-2025-27709SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published06/09/2025 | SeverityHigh |
CVE-2025-3835Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published06/09/2025 | SeverityCritical |
CVE-2025-41407SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/23/2025 | SeverityHigh |
CVE-2025-36527SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/23/2025 | SeverityHigh |
CVE-2025-41403SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/22/2025 | SeverityHigh |
CVE-2025-3836SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/22/2025 | SeverityHigh |
CVE-2025-3444Local File Inclusion | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus MSP | Published05/22/2025 | SeverityMedium |
CVE-2025-3834SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published05/14/2025 | SeverityHigh |
CVE-2025-3833SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADSelfService Plus | Published05/14/2025 | SeverityHigh |
CVE-2024-50053Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus | Published03/21/2025 | SeverityMedium |
CVE-2025-1724Account Takeover | Exploitation statusNot known exploited | FixYes | Affected productAnalytics Plus | Published03/17/2025 | SeverityHigh |
CVE-2025-1723Account takeover | Exploitation statusNot known exploited | FixYes | Affected productADSelfService Plus | Published03/03/2025 | SeverityHigh |
CVE-2024-9097IDOR | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published02/05/2025 | SeverityLow |
CVE-2024-41140Improper Authorization | Exploitation statusNot known exploited | FixYes | Affected productApplications Manager | Published01/29/2025 | SeverityHigh |
CVE-2024-52323Sensitive Data Exposure | Exploitation statusNot known exploited | FixYes | Affected productAnalytics Plus | Published11/27/2024 | SeverityHigh |
CVE-2024-49574SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published11/18/2024 | SeverityHigh |
CVE-2024-10839XML External Entity | Exploitation statusNot known exploited | FixYes | Affected productSharePoint Manager Plus | Published11/08/2024 | SeverityHigh |
CVE-2024-24409Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productADManager Plus | Published11/08/2024 | SeverityHigh |
CVE-2024-10203Agent Arbitrary File Deletion | Exploitation statusNot known exploited | FixYes | Affected productEndPoint Central | Published11/07/2024 | SeverityHigh |
CVE-2024-9459SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published11/05/2024 | SeverityHigh |
CVE-2024-36485SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published11/04/2024 | SeverityHigh |
CVE-2024-48878SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADManager Plus | Published11/04/2024 | SeverityHigh |
CVE-2024-5608SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published10/24/2024 | SeverityHigh |
CVE-2024-38868Incorrect Authorization | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published08/30/2024 | SeverityHigh |
CVE-2024-6204SQL injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published08/30/2024 | SeverityHigh |
CVE-2024-5546SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productPassword Manager Pro | Published08/28/2024 | SeverityHigh |
CVE-2024-41150Stored XSS | Exploitation statusNot known exploited | FixYes | Affected productServiceDesk Plus | Published08/23/2024 | SeverityMedium |
CVE-2024-38869Incorrect Authorization | Exploitation statusNot known exploited | FixYes | Affected productEndpoint Central | Published08/23/2024 | SeverityHigh |
CVE-2024-5586SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5556SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5490SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36514SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36515SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36516SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-36517SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5467SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/23/2024 | SeverityHigh |
CVE-2024-5466Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected productOpManager, Remote Monitoring and Management | Published08/23/2024 | SeverityHigh |
CVE-2024-36034SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-36035SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-36518SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-5487SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-5527SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productADAudit Plus | Published08/12/2024 | SeverityHigh |
CVE-2024-5678SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productApplications Manager | Published08/01/2024 | SeverityMedium |
CVE-2024-38872SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published07/26/2024 | SeverityHigh |
CVE-2024-38871SQL Injection | Exploitation statusNot known exploited | FixYes | Affected productExchange Reporter Plus | Published07/26/2024 | SeverityHigh |
CVE-2024-5471Agent takeover | Exploitation statusNot known exploited | FixYes | Affected productDDI Central | Published07/17/2024 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan