Zoho manageengine adaudit plus
This hub aggregates every CVE we track for Zoho manageengine adaudit plus, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
2
Critical
9
High
1
In CISA KEV
Severity distribution
HIGH9MEDIUM3CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
3
3
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Zoho manageengine adaudit plus.
- CVE-2025-41444SQL Injection8.3
- CVE-2025-36528SQL Injection8.3
- CVE-2025-27709SQL Injection8.3
- CVE-2025-41403SQL Injection8.3
- CVE-2025-3836SQL Injection8.3
- CVE-2025-3834SQL Injection8.1
- CVE-2024-36518SQL Injection8.3
- CVE-2024-5487SQL Injection8.3
- CVE-2024-5527SQL Injection8.3
- CVE-2024-36037Insufficient Access Control Vulnerability5.5
- CVE-2024-36036Insufficient Access Control Vulnerability4.2
- CVE-2023-50785Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.2.7
- CVE-2023-37308Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.5.4
- CVE-2022-47966Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because ...KEV9.8
- CVE-2022-28219Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.9.8
Product normalization is registry-driven with AI assist and human review. How it works