Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · zohocorp

zohocorp

· 97 Critical

Total CVEs

550

Critical

97

Products

69

Search All CVEs →

550

Products (69)

manageengine applications manager56 CVEsmanageengine opmanager56 CVEsmanageengine admanager plus53 CVEsmanageengine adaudit plus52 CVEsmanageengine adselfservice plus51 CVEsmanageengine servicedesk plus50 CVEsmanageengine desktop central48 CVEsmanageengine supportcenter plus31 CVEsmanageengine netflow analyzer28 CVEsmanageengine exchange reporter plus28 CVEsmanageengine assetexplorer26 CVEsmanageengine servicedesk plus msp26 CVEsmanageengine password manager pro22 CVEsmanageengine eventlog analyzer19 CVEsmanageengine pam36014 CVEsmanageengine remote access plus14 CVEsmanageengine network configuration manager14 CVEsmanageengine firewall analyzer12 CVEsmanageengine access manager plus11 CVEsmanageengine it3609 CVEsmanageengine log3609 CVEsmanageengine oputils8 CVEsmanageengine endpoint central8 CVEsmanageengine analytics plus7 CVEsmanageengine datasecurity plus6 CVEsmanageengine opmanager plus6 CVEsmanageengine opmanager msp6 CVEsmanageengine key manager plus5 CVEsservicedesk plus5 CVEsmanageengine cloud security plus5 CVEsmanageengine social it plus5 CVEsmanageengine sharepoint manager plus5 CVEsmanageengine application control plus4 CVEswebnms framework4 CVEsmanageengine m365 manager plus4 CVEsmanageengine device control plus4 CVEsmanageengine mobile device manager plus3 CVEsmanageengine ad3603 CVEsmanageengine browser security plus3 CVEsmanageengine o365 manager plus3 CVEsmanageengine patch connect plus3 CVEsmanageengine patch manager plus3 CVEsmanageengine recoverymanager plus3 CVEsmanageengine vulnerability manager plus3 CVEsmanageengine os deployer2 CVEsfirewall analyzer2 CVEszoho crm lead magnet2 CVEsmanageengine endpoint dlp plus2 CVEsmanageengine remote monitoring and management central2 CVEsmanageengine desktop central managed service providers2 CVEsmanageengine ddi central2 CVEszoho forms2 CVEsmanageengine opstor2 CVEsmanageengine m365 security plus2 CVEsmanageengine log360 ueba2 CVEsmanageengine endpoint central msp1 CVEslog3601 CVEssite24x7 mobile network poller1 CVEsmanageengine applications control plus1 CVEsmanageengine firewall1 CVEswebnms1 CVEsmanageengine appcreator1 CVEsmanageengine recovermanager plus1 CVEsmanageengine recovery manager plus1 CVEsmanageengine supportcentre plus1 CVEsdesktop central1 CVEsmanageengine remote monitoring and management1 CVEspassword manager pro1 CVEsmanageengine secure gateway server1 CVEs

Recent Vulnerabilities

View all 550
CVE-2026-4108HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.

CVE-2026-4107HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

CVE-2026-3880HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report.

CVE-2026-3879HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report.

CVE-2026-28703HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report.

CVE-2026-28756HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report.

CVE-2026-28754HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report.

CVE-2026-27655HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report.

CVE-2025-9435MEDIUM 5.5

Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module

CVE-2025-11669HIGH 8.1

Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.

CVE-2025-11250CRITICAL 9.1

Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper filter configurations.

CVE-2025-9787MEDIUM 6.1

Zohocorp ManageEngine Applications Manager versions 177400 and below are vulnerable to Stored Cross-Site Scripting vulnerability in the NOC view.

CVE-2025-11670MEDIUM 6.4

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

CVE-2025-7633HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Custom report.

CVE-2025-7632HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Public Folders report.

CVE-2025-7430HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Folder Message Count and Size report.

CVE-2025-7429HIGH 7.3

Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in the Mails Deleted or Moved report.

CVE-2025-5347MEDIUM 6.3

Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module.

CVE-2025-5343MEDIUM 6.3

Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option.

CVE-2025-5342MEDIUM 4.3

Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

CVE-2025-11248LOW 3.2

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token.

CVE-2025-6239MEDIUM 6.5

Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor.

CVE-2025-10020HIGH 8.5

Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.

CVE-2025-9428HIGH 8.3

Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api.

CVE-2025-7473MEDIUM 5.2

Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.