ZeroHour

Vulnerabilities

505 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3324
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.

NVD description · AI analysis pending
8.21%
  • zohocorp manageengine log360
CVE-2026-4107
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

NVD description · AI analysis pending
5.4
group max
<1%
  • zohocorp manageengine exchange reporter plus
CVE-2025-9435
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

NVD description · AI analysis pending
5.5<1%
  • zohocorp manageengine admanager plus
CVE-2025-11669
Zohocorp ManageEngine PAM360 versions before 8202;

Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.

NVD description · AI analysis pending
8.1<1%
  • zohocorp manageengine pam360
  • zohocorp manageengine access manager plus
  • zohocorp manageengine password manager pro
CVE-2025-11250
Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

NVD description · AI analysis pending
9.11%
  • zohocorp manageengine adselfservice plus
CVE-2025-9787
Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

NVD description · AI analysis pending
6.11%
  • zohocorp manageengine applications manager
CVE-2025-11670
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

NVD description · AI analysis pending
4.3<1%
  • zohocorp manageengine admanager plus
CVE-2025-7633
+3 in the same advisory: …7632 …7430 …7429
Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

NVD description · AI analysis pending
6.1
group max
<1%
  • zohocorp manageengine exchange reporter plus
CVE-2025-5342
+2 in the same advisory: …5343 …5347
Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

NVD description · AI analysis pending
6.5
group max
1%
  • zohocorp manageengine exchange reporter plus
CVE-2025-11248
ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue.

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.

NVD description · AI analysis pending
4.3<1%
  • zohocorp manageengine endpoint central
CVE-2025-6239
Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

NVD description · AI analysis pending
6.5<1%
  • zohocorp manageengine applications manager
CVE-2025-10020
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

NVD description · AI analysis pending
8.85%
  • zohocorp manageengine admanager plus
CVE-2025-9428
Authenticated SQL Injection in ManageEngine Analytics Plus (builds 6171 and prior)

ManageEngine Analytics Plus build 6171 and earlier contain a SQL injection flaw (CWE-89) in the key update API. A low-privileged, authenticated user can send crafted input to this API endpoint, causing attacker-controlled SQL to execute against the product's backend database. Per the CVSS 8.8 rating, successful exploitation carries high impact on confidentiality, integrity, and availability, meaning an attacker could read, alter, or disrupt the analytics data held by the application. Any organization running an affected build of Analytics Plus is exposed, though exploitation requires valid credentials on the system. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the 25.7% EPSS score (98th percentile) signals an elevated likelihood of exploitation within the next 30 days.

Do: Upgrade ManageEngine Analytics Plus to a build later than 6171 as directed by ManageEngine's security advisory, and confirm the installed build number in the product before and after patching. Because exploitation requires valid low-privileged credentials, audit which accounts can reach the key update API, restrict that access to trusted users, and review application/database logs for unexpected queries. Given the elevated EPSS, monitor for a public PoC or CISA KEV addition.

8.826%
  • Zoho Corporation ManageEngine Analytics Plus builds 6171 and prior
moderatelikely on the order of thousands to low tens of thousands of enterprise deployments (no official install-base figure is published)
CVE-2025-7473
+1 in the same advisory: …5496
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.

NVD description · AI analysis pending
5.3
group max
<1%
  • zohocorp manageengine endpoint central
CVE-2025-5494
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup.

ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.

NVD description · AI analysis pending
7.8<1%
  • zohocorp manageengine endpoint central
CVE-2025-27930
Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

Zohocorp ManageEngine Applications Manager versions 176600 and prior are vulnerable to stored cross-site scripting in the File/Directory monitor.

NVD description · AI analysis pending
5.4<1%
  • zohocorp manageengine applications manager
CVE-2025-5966
+1 in the same advisory: …5366
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.

NVD description · AI analysis pending
8.11%
  • zohocorp manageengine exchange reporter plus
CVE-2025-41444
+2 in the same advisory: …36528 …27709
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module.

NVD description · AI analysis pending
8.31%
  • zohocorp manageengine adaudit plus
CVE-2025-3835
Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

Zohocorp ManageEngine Exchange Reporter Plus versions 5721 and prior are vulnerable to Remote code execution in the Content Search module.

NVD description · AI analysis pending
9.62%
  • zohocorp manageengine exchange reporter plus
CVE-2025-36527
+1 in the same advisory: …41407
Authenticated SQL injection in report export in Zoho ManageEngine ADAudit Plus

ManageEngine ADAudit Plus, Zoho's Active Directory auditing product, contains a SQL injection flaw (CWE-89) in its report export functionality in builds below 8511. An authenticated user with low privileges can trigger it by initiating a report export, where unsanitized input is incorporated into the underlying database query. A successful attacker can read or tamper with data in the product's audit database, with high confidentiality and integrity impact and limited availability impact per the CVSS score, potentially exposing sensitive directory activity records the tool has collected. Any organization running ADAudit Plus builds prior to 8511 is affected; the product's web console typically runs on-premises and is reachable from internal networks or VPN, which constrains attacker reach. No public PoC, CISA KEV listing, or confirmed in-the-wild exploitation is known, although EPSS assigns a 36.5% probability of exploitation within 30 days (98th percentile), suggesting elevated risk.

Do: Upgrade ADAudit Plus to build 8511 or later, which resolves this SQL injection. Until patched, restrict access to the web console and any externally reachable entry points (reverse proxies, VPN) to trusted accounts, and monitor report-export activity for anomalies. Review export/download logs for signs of abuse by low-privileged accounts.

8.337%
  • Zoho Corp ManageEngine ADAudit Plus all builds below 8511 (fixed in build 8511)
moderatelow tens of thousands of on-prem installations worldwide (typically one console per organization)
CVE-2025-3836
+1 in the same advisory: …41403
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report.

NVD description · AI analysis pending
8.36%
  • zohocorp manageengine adaudit plus
CVE-2025-3444
Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin m

Zohocorp ManageEngine ServiceDesk Plus MSP and SupportCenter Plus versions below 14920 are vulnerable to authenticated Local File Inclusion (LFI) in the Admin module, where help card content is loaded.

NVD description · AI analysis pending
6.52%
  • zohocorp manageengine servicedesk plus msp
  • zohocorp manageengine supportcenter plus
CVE-2025-3834
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.

NVD description · AI analysis pending
8.12%
  • zohocorp manageengine adaudit plus
CVE-2025-3833
Authenticated SQL Injection in ManageEngine ADSelfService Plus MFA Reports

CVE-2025-3833 is an SQL injection flaw (CWE-89) in the MFA reports function of Zoho ManageEngine ADSelfService Plus, affecting builds 6513 and earlier. It is triggered over the network by an authenticated user — any account with access to the self-service portal can reach the vulnerable MFA reports code, with no additional user interaction required. Successful injection gives the attacker high-impact read and write access to the backing database, potentially exposing directory/MFA-related data (e.g., user identity details, MFA contact information) and allowing modification of stored records. All organizations running ADSelfService Plus build 6513 or prior are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the flaw sits in the 99th EPSS percentile with a 44.4% probability of exploitation within 30 days, so defenders should treat it as a near-term risk.

Do: Upgrade all ADSelfService Plus instances to a fixed build released after 6513 (deploy the latest available build). In the meantime, restrict which accounts can access the MFA reports module and monitor the portal for anomalous report queries or database changes. Because exploitation requires valid portal credentials, prioritize patching for internet-exposed or externally reachable ADSelfService Plus portals and review MFA report data for signs of tampering.

8.144%
  • Zoho Corp (ManageEngine) ManageEngine ADSelfService Plus 6513 and prior
largetens of thousands of enterprise deployments, covering likely hundreds of thousands to low millions of AD end users
CVE-2024-50053
Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in t

Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.

NVD description · AI analysis pending
5.41%
  • zohocorp manageengine servicedesk plus
  • zohocorp manageengine servicedesk plus msp
  • zohocorp manageengine supportcentre plus
CVE-2025-1723
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling.

Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.

NVD description · AI analysis pending
8.11%
  • zohocorp manageengine adselfservice plus
CVE-2024-9097
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.

NVD description · AI analysis pending
4.3<1%
  • zohocorp manageengine endpoint central
CVE-2024-41140
Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.

NVD description · AI analysis pending
6.5<1%
  • zohocorp manageengine applications manager
CVE-2024-52323
Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive to

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account.

NVD description · AI analysis pending
8.11%
  • zohocorp manageengine analytics plus
CVE-2024-49574
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

NVD description · AI analysis pending
8.84%
  • zohocorp manageengine adaudit plus
CVE-2024-10839
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

NVD description · AI analysis pending
8.12%
  • zohocorp manageengine sharepoint manager plus
CVE-2024-24409
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

NVD description · AI analysis pending
8.86%
  • zohocorp manageengine admanager plus