Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zohocorp

First CVE: Jun 22, 2009Active for: 17 yearsTotal CVEs: 558
69.2
VTI Score
TOP TARGET

Zohocorp's vulnerability footprint spans a substantial portfolio of IT operations and identity-management applications within the ManageEngine product line, serving organizations ranging from small businesses to large enterprises and presenting a considerable attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting both the privileged access these management platforms command and their appeal as high-value targets. The exposure recurs consistently across flagship products such as Applications Manager, OpManager, ADManager Plus, ADaudit Plus, and ADSelfService Plus, and concentrates through web-application weakness classes including cross-site scripting, SQL injection, path traversal, and unrestricted file upload—flaws endemic to web-facing administrative interfaces. Defenders should prioritize this vendor's patches for internet-connected instances, maintain strict network segmentation for management layers, and track these products in vulnerability assessments with elevated urgency. Current exploitation activity and severity distributions are shown alongside this summary.

FAUCET AI Generated
558
Total CVEs
More Total CVEs than 100% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
1.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Zohocorp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 22, 2009
17 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Self-Reporting Analysis

Of all the CVEs published by Zohocorp as a CNA, 89.6% affect products that Zohocorp develops as a vendor.

89.6%
10.4%
Self-reported: 103 (89.6%)
Third-party: 12 (10.4%)

Of all the CVEs published that affect products developed by Zohocorp, 18.5% are self-published by Zohocorp as a CNA.

18.5%
81.5%
Self-published: 103 (18.5%)
Other CNAs: 455 (81.5%)

Products(69 total)

Top CVEs

Signals from CVEs in this vendor scope (558 CVEs).

558 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-47966CRITICAL
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java
Jan 18, 20239.899YESYES
CVE-2020-10189CRITICAL
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is relat
Mar 6, 20209.899YESYES
CVE-2022-35405CRITICAL
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager P
Jul 19, 20229.898YESYES
CVE-2021-44077CRITICAL
Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. Thi
Nov 29, 20219.898YESYES
CVE-2021-40539CRITICAL
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resultant remote code execution.
Sep 7, 20219.898YESYES
CVE-2021-44515CRITICAL
Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server, as exploited in the wild in December 2021. For Enterprise
Dec 12, 20219.897YESYES
CVE-2021-37415CRITICAL
Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
Sep 1, 20219.897YESYES
CVE-2022-28810MEDIUM
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary operating OS commands as SYSTEM via the policy custom script
Apr 18, 20226.893YESYES
CVE-2019-8394MEDIUM
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via login page customization.
Feb 17, 20196.593YESYES
CVE-2022-28219CRITICAL
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
Apr 5, 20229.891NOYES
View all 558 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products558 CVEs
39%
34%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (3.9%)
Network488 (87.5%)
Unknown45 (8.1%)
Physical2 (0.4%)
Adjacent Network1 (0.2%)
Attack Complexity
Low503 (90.1%)
High10 (1.8%)
Unknown45 (8.1%)
User Interaction
None377 (67.6%)
Unknown45 (8.1%)
Required136 (24.4%)
Privileges Required
Low171 (30.6%)
High38 (6.8%)
None304 (54.5%)
Unknown45 (8.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (558 CVEs).

CISA KEV
9 CVEs
1.6% of CVEs· 99th percentile
Metasploit
30 CVEs
5.4% of CVEs· 98th percentile
Nuclei
23 CVEs
4.1% of CVEs· 95th percentile
ExploitDB
71 CVEs
12.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zohocorp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zohocorp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zohocorp's Products

View all 12 CNAs →

Top CWEs