« Volver al listado

Zohocorp

Zohocorp Manageengine Log360: vulnerabilidades y CVE

Zohocorp Manageengine Log360 tiene 10 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses1
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-3324Alta (8.2)2.1%—16 abr 2026
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
CVE-2023-35785Alta (8.1)2.4%—28 ago 2023
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data…
CVE-2021-20136Crítica (9.8)11%—1 nov 2021
ManageEngine Log360 Builds < 5235 are affected by an improper access control vulnerability allowing database configuration overwrite. An unauthenticated remote attacker can send a specially crafted message to Log360 to…
CVE-2021-40178Media (6.1)0.82%—29 ago 2021
Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
CVE-2021-40177Crítica (9.8)4.6%—29 ago 2021
Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
CVE-2021-40176Media (6.1)0.82%—29 ago 2021
Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
CVE-2021-40175Crítica (9.8)7.0%—29 ago 2021
Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
CVE-2021-40174Alta (8.8)0.99%—29 ago 2021
Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
CVE-2021-40172Alta (8.8)0.99%—29 ago 2021
Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
CVE-2020-24786Crítica (9.8)13%—31 ago 2020
An issue was discovered in Zoho ManageEngine Exchange Reporter Plus before build number 5510, AD360 before build number 4228, ADSelfService Plus before build number 5817, DataSecurity Plus before build number 6033,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts1
  2. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Zohocorp