Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2019-25581
i-doit CMDB 1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting maliciou…
I Doit
No fix yet
MEDIUM 6.5
CVE-2019-25582
i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating th…
I Doit
No fix yet
MEDIUM 6.1
CVE-2024-8750
Cross-site Scripting (XSS) vulnerability in idoit pro version 28. This vulnerability allows an attacker to retrieve session details of an authenticat…
I Doit
Mitigation only
HIGH 7.5
CVE-2024-8749
SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter…
I Doit
Mitigation only
MEDIUM 5.4
CVE-2023-46003
I-doit pro 25 and below is vulnerable to Cross Site Scripting (XSS) via index.php.
I Doit
after 25
CRITICAL 9.8
CVE-2023-37756
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easi…
I Doit
after 25
CRITICAL 9.8
CVE-2023-37755
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or promp…
I Doit
after 25
MEDIUM 6.5
CVE-2023-37739
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
I Doit
after 25
MEDIUM 5.4
CVE-2023-34830
i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.
I Doit
after 24
MEDIUM 5.4
CVE-2021-3151
i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web …
I Doit
1.16.0+
HIGH 8.8
CVE-2020-13826
A CSV injection (aka Excel Macro Injection or Formula Injection) issue in i-doit 1.14.2 allows an attacker to execute arbitrary commands via a Title …
I Doit
after 1.14.2
MEDIUM 6.1
CVE-2020-13825
A cross-site scripting (XSS) vulnerability in i-doit 1.14.2 allows remote attackers to inject arbitrary web script or HTML via the viewMode, tvMode, …
I Doit
after 1.14.2
CRITICAL 9.8
CVE-2019-1010248
Synetics GmbH I-doit 1.12 and earlier is affected by: SQL Injection. The impact is: Unauthenticated mysql database access. The component is: Web logi…
I Doit
after 1.12
MEDIUM 6.1
CVE-2019-6965
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
I Doit
Mitigation only
HIGH 7.2
CVE-2018-20159EPSS 10%
i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with …
I Doit
No fix yet
HIGH 7.5
CVE-2014-1597
SQL injection vulnerability in the CMDB web application in synetics i-doit pro before 1.2.5 and i-doit open allows remote attackers to execute arbitr…
I Doit
after 1.2.4