Vulnerabilidades em zohocorp
54 resultadosAnálise Vexday
A Zoho Corporation apresenta footprint reduzido de vulnerabilidades com apenas 1 CVE registrado, classificado como crítico e relacionado a falha de autenticação (CWE-287). Embora nenhuma vulnerabilidade esteja sob exploração ativa conhecida, a recente publicação nos últimos 90 dias recomenda atenção imediata, particularmente em ambientes que dependem da autenticação como controle de segurança primário.
CVE-2025-9428HIGHSQL InjectionEPSS 27.4%CVE-2026-1367HIGHSQL InjectionEPSS 7.7%CVE-2026-6516CRITICALRemote Code ExecutionEPSS 4.9%CVE-2025-10020HIGHCommand InjectionEPSS 4.5%CVE-2025-9223HIGHCommand InjectionEPSS 4.2%CVE-2026-11374CRITICALAccount Takeover via Predictable SSO Ticket GenerationEPSS 2.5%CVE-2025-8324CRITICALSQL InjectionEPSS 1.7%CVE-2026-2740HIGHRemote Code ExecutionEPSS 1.7%CVE-2026-12571CRITICALAuthentication Bypass Leading to Account TakeoverEPSS 1.6%CVE-2026-11840HIGHSQL InjectionEPSS 1.6%CVE-2025-11250CRITICALAuthentication BypassEPSS 1.6%CVE-2026-18912HIGHManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticateEPSS 1.5%CVE-2026-14828HIGHZohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 EPSS 1.4%CVE-2026-5785HIGHSQL InjectionEPSS 1.4%CVE-2025-1724HIGHAccount TakeoverEPSS 1.3%CVE-2026-3324HIGHAuthentication BypassEPSS 1.3%CVE-2026-3183HIGHMulti Factor Auth BypassEPSS 1.2%CVE-2025-9787MEDIUMStored XSSEPSS 1.1%CVE-2026-18911HIGHManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send reqEPSS 1.1%CVE-2025-5342MEDIUMDenial of Service (DoS)EPSS 1.1%