Zohocorp

First CVE: Jan 11, 2024Active for: 3 years
115
CVEs Published
More CVEs Published than 71% of tracked CNAs
38.3
Avg CVEs / Year
More Avg CVEs / Year than 80% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Zohocorp as a CNA, 89.6% affect products that Zohocorp develops as a vendor.

89.6%
10.4%
Self-reported: 103Third-party: 12

Of all the CVEs published that affect products developed by Zohocorp, 18.5% are self-published by Zohocorp as a CNA.

18.5%
81.5%
Self-published: 103Published by other CNAs: 455

Trends Over Time

The number and severity of CVEs published by Zohocorp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 11, 2024
2 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by Zohocorp as a CNA, regardless of affected vendor or product.

115 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unau
Jun 23, 20269.043NONO
Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.
Oct 21, 20258.842NONO
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
Jul 23, 202610.039NONO
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
May 14, 20258.139NONO
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
Nov 8, 20248.839NOYES
Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports.
May 23, 20258.338NONO
Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.
Jul 29, 20248.337NONO
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code executi
May 21, 20268.435NONO
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option.
Feb 23, 20268.332NONO
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.
Jan 13, 20269.132NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA115 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local6 (5.2%)
Network109 (94.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low111 (96.5%)
High4 (3.5%)
Unknown0 (0.0%)
User Interaction
None84 (73.0%)
Unknown0 (0.0%)
Required31 (27.0%)
Privileges Required
Low88 (76.5%)
High13 (11.3%)
None14 (12.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (115 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Zohocorp as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Zohocorp as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs