Vulnerability index

Browse CVEs

40 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-44231 RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa… Request Tracker 5.0.10 / 6.0.3+ Fix from $2,3002026-07-20 MEDIUM 6.1 CVE-2026-44230 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not in… Request Tracker 5.0.10 / 6.0.3+ Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-44229 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a… Request Tracker No fix yet Fix from $1,6002026-07-20 MEDIUM 6.1 CVE-2026-44227 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scri… Request Tracker 6.0.3+ Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-44228 RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Script… Request Tracker 6.0.3+ Fix from $1,6002026-07-20 MEDIUM 6.1 CVE-2026-6841 Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft… Request Tracker 5.0.10 / 6.0.3+ Fix from $1,6002026-05-21 MEDIUM 6.1 CVE-2025-30087 Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted parameters in a search URL. Request Tracker 4.4.8 / 5.0.8+ Fix from $1,6002025-05-28 MEDIUM 6.1 CVE-2025-31500 Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. Request Tracker 5.0.8+ Fix from $1,6002025-05-28 MEDIUM 6.1 CVE-2025-31501 Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. Request Tracker 4.4.8 / 5.0.8+ Fix from $1,6002025-05-28 HIGH 7.5 CVE-2023-45024 Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder. Request Tracker 5.0.5+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-41259 Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in an email … Request Tracker 4.4.7 / 5.0.5+ Fix from $1,9502023-11-03 HIGH 7.5 CVE-2023-41260 Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API calls. Request Tracker 4.4.7 / 5.0.5+ Fix from $1,9502023-11-03 CRITICAL 9.1 CVE-2022-25800 Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool. Request Tracker For Incident Response 4.0.3 / 5.0.3+ Fix from $2,3002022-07-14 CRITICAL 9.1 CVE-2022-25801 Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools. Request Tracker For Incident Response 4.0.3 / 5.0.3+ Fix from $2,3002022-07-14 MEDIUM 6.1 CVE-2022-25802 Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attachment. Request Tracker 4.4.6 / 5.0.3+ Fix from $1,6002022-07-14 MEDIUM 6.1 CVE-2022-25803 Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search. Request Tracker 5.0.3+ Fix from $1,6002022-07-14 HIGH 8.8 CVE-2017-5943 Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cro… Request Tracker Mitigation only Fix from $1,9502017-07-03 HIGH 8.8 CVE-2017-5944 The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authen… Request Tracker Mitigation only Fix from $1,9502017-07-03 MEDIUM 6.1 CVE-2016-6127 Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownl… Request Tracker Mitigation only Fix from $1,6002017-07-03 MEDIUM 5.9 CVE-2017-5361 Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time comparison algorithm for secrets, wh… Request Tracker Mitigation only Fix from $1,6002017-07-03 MEDIUM 5.0 CVE-2013-3737 The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (… Request Tracker Patch available Fix from $1,6002014-11-16 MEDIUM 5.0 CVE-2014-1474 Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denia… Rt after 0.01 Fix from $1,6002014-07-15 MEDIUM 6.8 CVE-2013-3370 Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remot… Rt Patch available Fix from $1,6002013-08-23 MEDIUM 6.0 CVE-2013-3369 Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pa… Rt Patch available Fix from $1,6002013-08-23 MEDIUM 5.0 CVE-2013-3373 CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP hea… Rt Patch available Fix from $1,6002013-08-23 MEDIUM 6.0 CVE-2012-4733 Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote a… Rt Patch available Fix from $1,6002013-08-23 MEDIUM 6.4 CVE-2012-6579 Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or sig… Request Tracker Patch available Fix from $1,6002013-07-24 HIGH 7.5 CVE-2013-3525 SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via th… Request Tracker after 4.0.9 Fix from $1,9502013-05-10 MEDIUM 6.8 CVE-2012-4732 Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before … Rt Patch available Fix from $1,6002012-11-11 MEDIUM 5.0 CVE-2012-4734 Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warn… Rt Mitigation only Fix from $1,6002012-11-11