Zohocorp
Zohocorp Manageengine Adaudit Plus: vulnerabilidades y CVE
Zohocorp Manageengine Adaudit Plus tiene 53 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 9 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE53
Últimos 12 meses1
Críticas9
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-47966 | Crítica (9.8) | 100% | ⚠ Explotación activa | 18 ene 2023 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6516 | Crítica (10) | 4.7% | — | 23 jul 2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. |
| CVE-2025-41444 | Alta (8.3) | 1.6% | — | 9 jun 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the alerts module. |
| CVE-2025-36528 | Alta (8.3) | 1.6% | — | 9 jun 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in Service Account Auditing reports. |
| CVE-2025-27709 | Alta (8.3) | 1.6% | — | 9 jun 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the Service Account Auditing reports. |
| CVE-2025-41407 | Alta (8.3) | 1.5% | — | 23 may 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection in the OU History report. |
| CVE-2025-36527 | Alta (8.3) | 37% | — | 23 may 2025 | Zohocorp ManageEngine ADAudit Plus versions below 8511 are vulnerable to SQL injection while exporting reports. |
| CVE-2025-41403 | Alta (8.3) | 1.7% | — | 22 may 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection while fetching service account audit data. |
| CVE-2025-3836 | Alta (8.3) | 5.9% | — | 22 may 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the logon events aggregate report. |
| CVE-2025-3834 | Alta (8.1) | 1.7% | — | 14 may 2025 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. |
| CVE-2024-49574 | Alta (8.8) | 3.6% | — | 18 nov 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module. |
| CVE-2024-36485 | Alta (8.8) | 3.2% | — | 4 nov 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option. |
| CVE-2024-5608 | Alta (8.1) | 2.5% | — | 24 oct 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature. |
| CVE-2024-5586 | Alta (8.8) | 5.2% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option. |
| CVE-2024-5556 | Alta (8.8) | 4.5% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module. |
| CVE-2024-5490 | Alta (8.8) | 4.0% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. |
| CVE-2024-5467 | Alta (8.8) | 4.5% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report. |
| CVE-2024-36517 | Alta (8.8) | 5.3% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module. |
| CVE-2024-36516 | Alta (8.8) | 4.4% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), both of which… |
| CVE-2024-36515 | Alta (8.8) | 4.5% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), both of which… |
| CVE-2024-36514 | Alta (8.8) | 4.0% | — | 23 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option. |
| CVE-2024-5527 | Alta (8.8) | 4.7% | — | 12 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration. |
| CVE-2024-5487 | Alta (8.8) | 4.7% | — | 12 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option. |
| CVE-2024-36518 | Media (5.4) | 3.1% | — | 12 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard. |
| CVE-2024-36035 | Alta (8.8) | 7.4% | — | 12 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording. |
| CVE-2024-36034 | Alta (8.8) | 7.4% | — | 12 ago 2024 | Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option. |
| CVE-2024-36037 | Media (5.5) | 0.46% | — | 27 may 2024 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings. |
| CVE-2024-36036 | Media (4.2) | 0.37% | — | 27 may 2024 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration. |
| CVE-2024-21791 | Alta (7.2) | 2.2% | — | 22 may 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin users cannot exploit this vulnerability. |
| CVE-2023-49335 | Alta (8.8) | 3.0% | — | 20 may 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details. |
| CVE-2023-49334 | Alta (8.8) | 3.0% | — | 20 may 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection while exporting a full summary report. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Zohocorp
Manageengine Opmanager · 63Manageengine Applications Manager · 59Manageengine Adselfservice Plus · 56Manageengine Admanager Plus · 53Manageengine Servicedesk Plus · 50Manageengine Desktop Central · 48Manageengine Supportcenter Plus · 31Manageengine Netflow Analyzer · 30Manageengine Exchange Reporter Plus · 28Manageengine Assetexplorer · 26Manageengine Servicedesk Plus MSP · 26Manageengine Password Manager PRO · 25