Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2023-53943 GLPI 9.5.7 contains a username enumeration vulnerability in the lost password recovery mechanism that allows attackers to validate email addresses. A… Glpi No fix yet Fix from $1,6002025-12-18 MEDIUM 6.1 CVE-2022-39181 GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads data directly from… Reports Mitigation only Fix from $1,6002022-11-17 MEDIUM 6.5 CVE-2022-29250 GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In versio… Glpi Mitigation only Fix from $1,6002022-06-09 CRITICAL 9.8 CVE-2021-44617 A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated. Glpi No fix yet Fix from $2,3002022-03-28 MEDIUM 6.1 CVE-2021-3486 GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code. Glpi No fix yet Fix from $1,6002021-05-26 HIGH 7.2 CVE-2020-11032 In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician … Glpi Mitigation only Fix from $1,9502020-05-05 MEDIUM 5.4 CVE-2019-1010307 GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege esc… Glpi No fix yet Fix from $1,6002019-07-15 HIGH 8.0 CVE-2016-7507 Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creat… Glpi Mitigation only Fix from $1,9502017-07-19 MEDIUM 5.4 CVE-2016-7509 Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a c… Glpi Mitigation only Fix from $1,6002017-07-19 HIGH 7.5 CVE-2016-7508 Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain cha… Glpi No fix yet Fix from $1,9502017-06-21 MEDIUM 6.5 CVE-2012-1037 PHP remote file inclusion vulnerability in front/popup.php in GLPI 0.78 through 0.80.61 allows remote authenticated users to execute arbitrary PHP co… Glpi Mitigation only Fix from $1,6002012-07-12