Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-43778EPSS 53% Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are … Barcode 2.6.1+ Fix from $1,9502021-11-24 HIGH 8.8 CVE-2021-39213 GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable… Glpi 9.5.6+ Fix from $1,9502021-09-15 MEDIUM 6.5 CVE-2021-39210 GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses … Glpi 9.5.6+ Fix from $1,6002021-09-15 MEDIUM 5.3 CVE-2021-39211 GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI an… Glpi 9.5.6+ Fix from $1,6002021-09-15 HIGH 8.8 CVE-2021-39209 GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Fo… Glpi 9.5.6+ Fix from $1,9502021-09-15 MEDIUM 6.1 CVE-2021-3486 GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code. Glpi No fix yet Fix from $1,6002021-05-26 HIGH 7.5 CVE-2021-21327 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,9502021-03-08 MEDIUM 6.5 CVE-2021-21326 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,6002021-03-08 MEDIUM 6.5 CVE-2021-21324 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,6002021-03-08 MEDIUM 6.1 CVE-2021-21313 GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In G… Glpi 9.5.4+ Fix from $1,6002021-03-03 MEDIUM 5.7 CVE-2021-21255 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi Patch available Fix from $1,6002021-03-02 MEDIUM 5.4 CVE-2021-21258 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In… Glpi 9.5.4+ Fix from $1,6002021-03-02 MEDIUM 6.5 CVE-2020-26212 GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk fe… Glpi 9.5.3+ Fix from $1,6002020-11-25 CRITICAL 9.1 CVE-2020-15175EPSS 71% In GLPI before version 9.5.2, the `​pluginimage.send.php​` endpoint allows a user to specify an image from a plugin. The parameters can be maliciousl… Glpi 9.5.2+ Fix from $2,3002020-10-07 HIGH 8.6 CVE-2020-15176 In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing… Glpi 9.5.2+ Fix from $1,9502020-10-07 MEDIUM 6.1 CVE-2020-15177 In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. The… Glpi 9.5.2+ Fix from $1,6002020-10-07 MEDIUM 5.3 CVE-2020-15217 In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in… Glpi 9.5.2+ Fix from $1,6002020-10-07 HIGH 7.5 CVE-2020-11031 In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user se… Glpi 9.5.0+ Fix from $1,9502020-09-23 HIGH 7.1 CVE-2020-15108 In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1. Glpi 9.5.1+ Fix from $1,9502020-07-17 HIGH 8.8 CVE-2020-11060EPSS 11% In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited… Glpi 9.4.6+ Fix from $1,9502020-05-12 MEDIUM 5.4 CVE-2020-11062 In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in vers… Glpi 9.4.6+ Fix from $1,6002020-05-12 MEDIUM 5.3 CVE-2020-5248 GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means … Glpi 9.4.6+ Fix from $1,6002020-05-12 MEDIUM 6.1 CVE-2020-11034EPSS 8% In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is f… Glpi 9.4.6+ Fix from $1,6002020-05-05 MEDIUM 5.4 CVE-2020-11036 In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items … Glpi 9.4.6+ Fix from $1,6002020-05-05 HIGH 7.2 CVE-2020-11032 In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician … Glpi Mitigation only Fix from $1,9502020-05-05 HIGH 8.8 CVE-2019-14666 GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads t… Glpi after 9.4.3 Fix from $1,9502019-09-25 MEDIUM 5.4 CVE-2019-1010307 GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege esc… Glpi No fix yet Fix from $1,6002019-07-15 MEDIUM 5.9 CVE-2019-13240 An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during… Glpi 9.4.1+ Fix from $1,6002019-07-10 MEDIUM 6.1 CVE-2019-13239 inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture. Glpi 9.4.3+ Fix from $1,6002019-07-04 HIGH 8.1 CVE-2019-10233 Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie. Glpi 9.4.1.1+ Fix from $1,9502019-03-27