Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I Doit HIGH 7.5
CVE-2019-25581

i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou…

No fix yet
Fix from $1,950 2026-03-21
I Doit MEDIUM 6.5
CVE-2019-25582

i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating th…

No fix yet
Fix from $1,600 2026-03-21
I Doit MEDIUM 6.1
CVE-2024-8750

Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticat…

Mitigation only
Fix from $1,600 2024-09-12
I Doit HIGH 7.5
CVE-2024-8749

SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter…

Mitigation only
Fix from $1,950 2024-09-12
I Doit MEDIUM 5.4
CVE-2023-46003

I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.

Fix: after 25
Fix from $1,600 2023-10-21
I Doit CRITICAL 9.8
CVE-2023-37756

I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easi…

Fix: after 25
Fix from $2,300 2023-09-14
I Doit CRITICAL 9.8
CVE-2023-37755

i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or promp…

Fix: after 25
Fix from $2,300 2023-09-14
I Doit MEDIUM 6.5
CVE-2023-37739

i-doit Pro v25 and below was discovered to be vulnerable to path traversal.

Fix: after 25
Fix from $1,600 2023-09-14
I Doit MEDIUM 5.4
CVE-2023-34830

i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.

Fix: after 24
Fix from $1,600 2023-06-27
I Doit MEDIUM 5.4
CVE-2021-3151

i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web …

Fix: 1.16.0+
Fix from $1,600 2021-02-27
I Doit HIGH 8.8
CVE-2020-13826

A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title …

Fix: after 1.14.2
Fix from $1,950 2020-08-20
I Doit MEDIUM 6.1
CVE-2020-13825

A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, …

Fix: after 1.14.2
Fix from $1,600 2020-08-20
I Doit CRITICAL 9.8
CVE-2019-1010248

Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web logi…

Fix: after 1.12
Fix from $2,300 2019-07-18
I Doit MEDIUM 6.1
CVE-2019-6965

An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.

Mitigation only
Fix from $1,600 2019-06-18
I Doit HIGH 7.2
CVE-2018-20159EPSS 10%

i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with …

No fix yet
Fix from $1,950 2018-12-15
I Doit HIGH 7.5
CVE-2014-1597

SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitr…

Fix: after 1.2.4
Fix from $1,950 2014-02-27