Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 9 of 9 CVEs matching "Zoho" · HIGH · CISA KEV

CVE-2022-28810KEV
High

Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.

ZohoEPSS 90.8%
CVE-2022-47966KEV
High

Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage of an outdated third-party dependency, Apache Santuario.

ZohoEPSS 94.4%
CVE-2022-35405KEV
High

Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.

ZohoEPSS 94.2%
CVE-2021-44515KEV
High

Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute arbitrary code in the Desktop Central MSP server.

ZohoEPSS 94.3%
CVE-2021-37415KEV
High

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication

ZohoEPSS 92.0%
CVE-2021-44077KEV
High

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution

ZohoEPSS 94.3%
CVE-2019-8394KEV
High

Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.

ZohoEPSS 87.3%
CVE-2020-10189KEV
High

Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.

ZohoEPSS 94.2%
CVE-2021-40539KEV
High

Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.

ZohoEPSS 94.4%