CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

zohocorp

manageengine_opmanager

12 known vulnerabilities · sorted by CVSS score

CVE-2021-44514
CRITICAL9.8

OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.

zohocorp / manageengine_opmanager+129
Network
Published Dec 9, 2021
CVE-2021-41075
CRITICAL9.8

The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module API.

zohocorp / manageengine_opmanager+117
Network
Published Oct 13, 2021
CVE-2021-40493
CRITICAL9.8

Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObject parameter of the getDataCollectionFailureReason API.

zohocorp / manageengine_opmanager+110
Network
Published Oct 13, 2021
CVE-2021-3287
CRITICAL9.8

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

zohocorp / manageengine_opmanager+65
Network
Published Apr 22, 2021
CVE-2020-28653
CRITICAL9.8

Zoho ManageEngine OpManager Stable build before 125203 (and Released build before 125233) allows Remote Code Execution via the Smart Update Manager (SUM) servlet.

zohocorp / manageengine_opmanager+58
Network
Published Feb 3, 2021
CVE-2022-29535
CRITICAL9.8

Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.

zohocorp / manageengine_opmanager+138
Network
Published May 5, 2022
CVE-2021-41288
CRITICAL9.8

Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.

zohocorp / manageengine_opmanager+119
Network
Published Sep 30, 2021
CVE-2021-20078
CRITICAL9.1

Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any directory or directories on the OS.

zohocorp / manageengine_opmanager+70
Network
Published Apr 1, 2021
CVE-2022-27908
HIGH8.8

Zoho ManageEngine OpManager before 125588 (and before 125603) is vulnerable to authenticated SQL Injection in the Inventory Reports module.

zohocorp / manageengine_opmanager+135
Network
Published Apr 18, 2022
CVE-2020-13818
HIGH7.5

In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.

zohocorp / manageengine_opmanager+25
Network
Published Jun 4, 2020
CVE-2020-11946
HIGH7.5

Zoho ManageEngine OpManager before 125120 allows an unauthenticated user to retrieve an API key via a servlet call.

zohocorp / manageengine_opmanager+13
Network
Published Apr 20, 2020
CVE-2020-12116
HIGH7.5

Zoho ManageEngine OpManager Stable build before 124196 and Released build before 125125 allows an unauthenticated attacker to read arbitrary files on the server by sending a crafted request.

zohocorp / manageengine_opmanager+79
Network
Published May 7, 2020