cbcvebase.

Zohocorp Manageengine Opmanager vulnerabilities

67 known vulnerabilities affecting zohocorp/manageengine_opmanager.

Total CVEs
67
CISA KEV
0
Public exploits
16
Exploited in wild
4
Severity breakdown
CRITICAL20HIGH33MEDIUM14

Vulnerabilities

Page 3 of 4
CVE-2026-12370P2HIGHCVSS 7.6fixed in 12.8.6682026-09-23
CVE-2026-12370 [HIGH] CWE-1336 CVE-2026-12370: ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.6 ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
nvd
CVE-2026-14913P3HIGHCVSS 8.8fixed in 12.8.6702026-09-23
CVE-2026-14913 [HIGH] CWE-89 CVE-2026-14913: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
nvd
CVE-2020-11527P3HIGHCVSS 7.5fixed in 12.4v12.42020-04-04
CVE-2020-11527 [HIGH] CVE-2020-11527: In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specia In Zoho ManageEngine OpManager before 12.4.181, an unauthenticated remote attacker can send a specially crafted URI to read arbitrary files.
nvd
CVE-2021-41075P3CRITICALCVSS 9.8fixed in 12.5v12.52021-10-13
CVE-2021-41075 [CRITICAL] CWE-89 CVE-2021-41075: The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in t The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.
nvd
CVE-2026-84787P3HIGHCVSS 8.1fixed in 12.8.7112026-09-23
CVE-2026-84787 [HIGH] CWE-250 CVE-2026-84787: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
nvd
CVE-2015-9107P3CRITICALCVSS 9.8v11.0v11.1+6 more2017-08-04
CVE-2015-9107 [CRITICAL] CWE-310 CVE-2015-9107: Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the creden Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.
nvd
CVE-2017-11559P3HIGHCVSS 7.5v12.22019-05-23
CVE-2017-11559 [HIGH] CWE-89 CVE-2017-11559: An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/ad An issue was discovered in ZOHO ManageEngine OpManager 12.2. The 'apiKey' parameter of "/api/json/admin/getmailserversettings" and "/api/json/dashboard/gotoverviewlist" is vulnerable to a Blind SQL Injection attack.
nvd
CVE-2026-76979P3HIGHCVSS 7.7fixed in 12.8.7102026-09-23
CVE-2026-76979 [HIGH] CWE-91 CVE-2026-76979: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
nvd
CVE-2026-15358P3HIGHCVSS 7.5fixed in 12.8.6712026-09-23
CVE-2026-15358 [HIGH] CWE-428 CVE-2026-15358: ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vuln ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
nvd
CVE-2022-35404P3HIGHCVSS 8.2fixed in 12.5v12.52022-07-18
CVE-2022-35404 [HIGH] CWE-20 CVE-2022-35404: ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to u ManageEngine Password Manager Pro 12100 and prior and OPManager 126100 and prior are vulnerable to unauthorized file and directory creation on a server machine.
nvd
CVE-2019-12133P3HIGHCVSS 7.8v12.32019-06-18
CVE-2019-12133 [HIGH] CWE-427 CVE-2019-12133: Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissio Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will effectively allow non-privileged use
nvd
CVE-2026-84789P3HIGHCVSS 7.1fixed in 12.8.7112026-09-23
CVE-2026-84789 [HIGH] CWE-639 CVE-2026-84789: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
nvd
CVE-2026-84791P3HIGHCVSS 7.1fixed in 12.8.7112026-09-23
CVE-2026-84791 [HIGH] CWE-639 CVE-2026-84791: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
nvd
CVE-2022-43473P3MEDIUMCVSS 5.4fixed in 12.6v12.62023-03-30
CVE-2022-43473 [MEDIUM] CWE-611 CVE-2022-43473: A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of Manage A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
nvd
CVE-2026-76980P3HIGHCVSS 7.4fixed in 12.8.7102026-09-23
CVE-2026-76980 [HIGH] CWE-20 CVE-2026-76980: ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
nvd
CVE-2019-17421P3HIGHCVSS 7.8v12.42019-11-21
CVE-2019-17421 [HIGH] CWE-276 CVE-2019-17421: Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12. Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
nvd
CVE-2017-11561P3MEDIUMCVSS 6.5v12.22019-05-23
CVE-2017-11561 [MEDIUM] CWE-434 CVE-2017-11561: An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any fi An issue was discovered in ZOHO ManageEngine OpManager 12.2. An authenticated user can upload any file they want to share in the "Group Chat" or "Alarm" section. This functionality can be abused by a malicious user by uploading a web shell.
nvd
CVE-2025-9227P4MEDIUMCVSS 6.5≤ 1286092025-11-11
CVE-2025-9227 [MEDIUM] CWE-79 CVE-2025-9227: Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
nvd
CVE-2018-18715P4MEDIUMCVSS 6.1v12.32018-11-20
CVE-2018-18715 [MEDIUM] CWE-79 CVE-2018-18715: Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS. Zoho ManageEngine OpManager 12.3 before 123219 has stored XSS.
nvd
CVE-2018-19288P4MEDIUMCVSS 6.1v11.4v11.5+1 more2018-11-15
CVE-2018-19288 [MEDIUM] CWE-79 CVE-2018-19288: Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API. Zoho ManageEngine OpManager 12.3 before Build 123223 has XSS via the updateWidget API.
nvd
Zohocorp Manageengine Opmanager vulnerabilities | cvebase