Zohocorp's vulnerability footprint spans a substantial portfolio of IT operations and identity-management applications within the ManageEngine product line, serving organizations ranging from small businesses to large enterprises and presenting a considerable attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the privileged access these management platforms command and their appeal as high-value targets. The exposure recurs consistently across flagship products such as Applications Manager, OpManager, ADManager Plus, ADaudit Plus, and ADSelfService Plus, and concentrates through web-application weakness classes including cross-site scripting, SQL injection, path traversal, and unrestricted file upload—flaws endemic to web-facing administrative interfaces. Defenders should prioritize this vendor's patches for internet-connected instances, maintain strict network segmentation for management layers, and track these products in vulnerability assessments with elevated urgency. Current exploitation activity and severity distributions are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zohocorp over time
Of all the CVEs published by Zohocorp as a CNA, 89.6% affect products that Zohocorp develops as a vendor.
Of all the CVEs published that affect products developed by Zohocorp, 18.5% are self-published by Zohocorp as a CNA.
Signals from CVEs in this vendor scope (558 CVEs).
558 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47966CRITICAL Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java | Jan 18, 2023 | 9.8 | 99 | YES | YES |
CVE-2020-10189CRITICAL Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is relat | Mar 6, 2020 | 9.8 | 99 | YES | YES |
CVE-2022-35405CRITICAL Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager P | Jul 19, 2022 | 9.8 | 98 | YES | YES |
CVE-2021-44077CRITICAL Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. Thi | Nov 29, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-40539CRITICAL Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution. | Sep 7, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-44515CRITICAL Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise | Dec 12, 2021 | 9.8 | 97 | YES | YES |
CVE-2021-37415CRITICAL Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication. | Sep 1, 2021 | 9.8 | 97 | YES | YES |
CVE-2022-28810MEDIUM Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script | Apr 18, 2022 | 6.8 | 93 | YES | YES |
CVE-2019-8394MEDIUM Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization. | Feb 17, 2019 | 6.5 | 93 | YES | YES |
CVE-2022-28219CRITICAL Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | Apr 5, 2022 | 9.8 | 91 | NO | YES |
Signals from CVEs in this vendor scope (558 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zohocorp.
Media articles that mention a CVE ID that affects a product developed by Zohocorp — matched by CVE ID, not by vendor name.