Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-25581 i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou… I Doit No fix yet Fix from $1,9502026-03-21 MEDIUM 6.5 CVE-2019-25582 i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating th… I Doit No fix yet Fix from $1,6002026-03-21 MEDIUM 6.1 CVE-2024-8750 Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticat… I Doit Mitigation only Fix from $1,6002024-09-12 HIGH 7.5 CVE-2024-8749 SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter… I Doit Mitigation only Fix from $1,9502024-09-12 MEDIUM 5.4 CVE-2023-46003 I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php. I Doit after 25 Fix from $1,6002023-10-21 CRITICAL 9.8 CVE-2023-37756 I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easi… I Doit after 25 Fix from $2,3002023-09-14 CRITICAL 9.8 CVE-2023-37755 i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or promp… I Doit after 25 Fix from $2,3002023-09-14 MEDIUM 6.5 CVE-2023-37739 i-doit Pro v25 and below was discovered to be vulnerable to path traversal. I Doit after 25 Fix from $1,6002023-09-14 MEDIUM 5.4 CVE-2023-34830 i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page. I Doit after 24 Fix from $1,6002023-06-27 MEDIUM 5.4 CVE-2021-3151 i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web … I Doit 1.16.0+ Fix from $1,6002021-02-27 HIGH 8.8 CVE-2020-13826 A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title … I Doit after 1.14.2 Fix from $1,9502020-08-20 MEDIUM 6.1 CVE-2020-13825 A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, … I Doit after 1.14.2 Fix from $1,6002020-08-20 CRITICAL 9.8 CVE-2019-1010248 Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web logi… I Doit after 1.12 Fix from $2,3002019-07-18 MEDIUM 6.1 CVE-2019-6965 An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. I Doit Mitigation only Fix from $1,6002019-06-18 HIGH 7.2 CVE-2018-20159EPSS 10% i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with … I Doit No fix yet Fix from $1,9502018-12-15 HIGH 7.5 CVE-2014-1597 SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitr… I Doit after 1.2.4 Fix from $1,9502014-02-27