Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2020-12780
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
Itop
2.7.1+
MEDIUM 6.1
CVE-2020-12778
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
Itop
2.7.1+
MEDIUM 5.4
CVE-2020-12779
Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
Itop
2.7.0+
MEDIUM 6.1
CVE-2020-11696
In Combodo iTop a menu shortcut name can be exploited with a stored XSS payload. This is fixed in all iTop packages (community, essential, profession…
Itop
2.6.4 / 2.7.0+
MEDIUM 6.1
CVE-2020-11697
In Combodo iTop, dashboard ids can be exploited with a reflective XSS payload. This is fixed in all iTop packages (community, essential, professional…
Itop
2.6.4 / 2.7.0+
HIGH 8.1
CVE-2019-19821
A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to access information and modify…
Itop
2.7+
HIGH 7.5
CVE-2019-13967
iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to launch a compile operation. T…
Itop
after 2.6.0
MEDIUM 6.1
CVE-2019-13965
Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via the param_file parameter to w…
Itop
after 2.6.0
MEDIUM 6.1
CVE-2019-13966
In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build the dashboard. This is similar …
Itop
after 2.6.0
HIGH 8.1
CVE-2019-11215
In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be accomplished by calling ajax.data…
Itop
after 2.6.0
HIGH 7.2
CVE-2019-10863EPSS 13%
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file wi…
Teemip
2.4.0+
HIGH 7.2
CVE-2018-10642EPSS 7%
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platfo…
Itop
after 2.4.1
MEDIUM 6.1
CVE-2015-6544EPSS 5%
Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject a…
Itop
2.2.0-2459+