ZOHO kayıtları
zoho üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %36,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-269 Improper Privilege Management1
- CWE-310 Cryptographic Issues1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2019-5963İstismar yok | Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of adzoho · salesiq · CWE-352 | Yüksek8,8 | — | %1,0 | 5 Tem 2019 |
35İzleyin | CVE-2019-15645İstismar yok | The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.zoho · salesiq · CWE-352 | Yüksek8,8 | — | %0,7 | 27 Ağu 2019 |
35İzleyin | CVE-2021-42956İstismar yok | Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability.zoho · manageengine remote access plus server · CWE-269 | Yüksek8,8 | — | %0,7 | 17 Kas 2021 |
35İzleyin | CVE-2024-37225İstismar yok | WordPress Zoho Marketing Automation plugin <= 1.2.7 - SQL Injection vulnerabilityzoho · marketing automation · CWE-89 | Yüksek8,8 | — | %0,5 | 9 Tem 2024 |
35İzleyin | CVE-2024-32441İstismar yok | WordPress Zoho Campaigns plugin <= 2.0.7 - Cross Site Request Forgery (CSRF) vulnerabilityzoho · zoho campaigns · CWE-352 | Yüksek8,8 | — | %0,2 | 15 Nis 2024 |
35İzleyin | CVE-2024-32442İstismar yok | WordPress Zoho Campaigns plugin <= 2.0.7 - Cross Site Request Forgery (CSRF) vulnerabilityzoho · zoho campaigns · CWE-352 | Yüksek8,8 | — | %0,2 | 15 Nis 2024 |
34İzleyin | CVE-2024-30239İstismar yok | WordPress Zoho Campaigns plugin <= 2.0.6 - SQL Injection vulnerabilityzoho campaigns · zoho campaigns · CWE-89 | Yüksek8,5 | — | %0,5 | 28 Mar 2024 |
24İzleyin | CVE-2019-5962İstismar yok | Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unspzoho · salesiq · CWE-79 | Orta6,1 | — | %1,6 | 5 Tem 2019 |
24İzleyin | CVE-2019-15644İstismar yok | The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.zoho · salesiq · CWE-79 | Orta6,1 | — | %0,9 | 27 Ağu 2019 |
21İzleyin | CVE-2019-19306İstismar yok | The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.zoho · lead magnet · CWE-79 | Orta5,4 | — | %1,1 | 26 Kas 2019 |
21İzleyin | CVE-2014-6686İstismar yok | The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, whiczoho · zoho books - accounting app · CWE-310 | Orta5,4 | — | %0,3 | 23 Eyl 2014 |
- CVE-2019-596335İzleyin
Cross-site request forgery (CSRF) vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to hijack the authentication of ad
YüksekCVSS 8,8İstismar yokEPSS %1zoho · salesiq5 Tem 2019
- CVE-2019-1564535İzleyin
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1zoho · salesiq27 Ağu 2019
- CVE-2021-4295635İzleyin
Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %1zoho · manageengine remote access plus server17 Kas 2021
- CVE-2024-3722535İzleyin
WordPress Zoho Marketing Automation plugin <= 1.2.7 - SQL Injection vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0zoho · marketing automation9 Tem 2024
- CVE-2024-3244135İzleyin
WordPress Zoho Campaigns plugin <= 2.0.7 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0zoho · zoho campaigns15 Nis 2024
- CVE-2024-3244235İzleyin
WordPress Zoho Campaigns plugin <= 2.0.7 - Cross Site Request Forgery (CSRF) vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0zoho · zoho campaigns15 Nis 2024
- CVE-2024-3023934İzleyin
WordPress Zoho Campaigns plugin <= 2.0.6 - SQL Injection vulnerability
YüksekCVSS 8,5İstismar yokEPSS %1zoho campaigns · zoho campaigns28 Mar 2024
- CVE-2019-596224İzleyin
Cross-site scripting vulnerability in Zoho SalesIQ 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unsp
OrtaCVSS 6,1İstismar yokEPSS %2zoho · salesiq5 Tem 2019
- CVE-2019-1564424İzleyin
The zoho-salesiq plugin before 1.0.9 for WordPress has stored XSS.
OrtaCVSS 6,1İstismar yokEPSS %1zoho · salesiq27 Ağu 2019
- CVE-2019-1930621İzleyin
The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
OrtaCVSS 5,4İstismar yokEPSS %1zoho · lead magnet26 Kas 2019
- CVE-2014-668621İzleyin
The Zoho Books - Accounting App (aka com.zoho.books) application 3.1.9 for Android does not verify X.509 certificates from SSL servers, whic
OrtaCVSS 5,4İstismar yokEPSS %0zoho · zoho books - accounting app23 Eyl 2014