Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2021-43778EPSS 53%
Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are …
Barcode
2.6.1+
HIGH 8.8
CVE-2021-39213
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable…
Glpi
9.5.6+
MEDIUM 6.5
CVE-2021-39210
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses …
Glpi
9.5.6+
MEDIUM 5.3
CVE-2021-39211
GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI an…
Glpi
9.5.6+
HIGH 8.8
CVE-2021-39209
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Fo…
Glpi
9.5.6+
MEDIUM 6.1
CVE-2021-3486
GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
Glpi
No fix yet
HIGH 7.5
CVE-2021-21327
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
MEDIUM 6.5
CVE-2021-21326
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
MEDIUM 6.5
CVE-2021-21324
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
MEDIUM 6.1
CVE-2021-21313
GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In G…
Glpi
9.5.4+
MEDIUM 5.7
CVE-2021-21255
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
Patch available
MEDIUM 5.4
CVE-2021-21258
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In…
Glpi
9.5.4+
MEDIUM 6.5
CVE-2020-26212
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk fe…
Glpi
9.5.3+
CRITICAL 9.1
CVE-2020-15175EPSS 71%
In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciousl…
Glpi
9.5.2+
HIGH 8.6
CVE-2020-15176
In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing…
Glpi
9.5.2+
MEDIUM 6.1
CVE-2020-15177
In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. The…
Glpi
9.5.2+
MEDIUM 5.3
CVE-2020-15217
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in…
Glpi
9.5.2+
HIGH 7.5
CVE-2020-11031
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user se…
Glpi
9.5.0+
HIGH 7.1
CVE-2020-15108
In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1.
Glpi
9.5.1+
HIGH 8.8
CVE-2020-11060EPSS 11%
In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited…
Glpi
9.4.6+
MEDIUM 5.4
CVE-2020-11062
In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in vers…
Glpi
9.4.6+
MEDIUM 5.3
CVE-2020-5248
GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means …
Glpi
9.4.6+
MEDIUM 6.1
CVE-2020-11034EPSS 8%
In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is f…
Glpi
9.4.6+
MEDIUM 5.4
CVE-2020-11036
In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items …
Glpi
9.4.6+
HIGH 7.2
CVE-2020-11032
In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician …
Glpi
Mitigation only
HIGH 8.8
CVE-2019-14666
GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads t…
Glpi
after 9.4.3
MEDIUM 5.4
CVE-2019-1010307
GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege esc…
Glpi
No fix yet
MEDIUM 5.9
CVE-2019-13240
An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during…
Glpi
9.4.1+
MEDIUM 6.1
CVE-2019-13239
inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture.
Glpi
9.4.3+
HIGH 8.1
CVE-2019-10233
Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
Glpi
9.4.1.1+