Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-8924
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthentica…
Servicenow
Mitigation only
CRITICAL 10.0
CVE-2024-8923
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…
Servicenow
Mitigation only
CRITICAL 9.8
CVE-2024-4879 KEVEPSS 100%
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabili…
Servicenow
Mitigation only
CRITICAL 9.8
CVE-2024-5217 KEVEPSS 100%
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. Th…
Servicenow
Mitigation only
MEDIUM 6.1
CVE-2023-1298
ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow …
Servicenow
Mitigation only
MEDIUM 6.5
CVE-2022-43684
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality.
Additional…
Servicenow
No fix yet
MEDIUM 5.4
CVE-2023-1209
Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.
Servicenow
Mitigation only
MEDIUM 6.1
CVE-2022-46389
There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, S…
Servicenow
Mitigation only
MEDIUM 6.1
CVE-2022-46886
There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai…
Servicenow
Mitigation only
MEDIUM 6.1
CVE-2022-39048
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade a…
Servicenow
Mitigation only
MEDIUM 6.1
CVE-2022-38172
ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.
Servicenow
Mitigation only
MEDIUM 6.1
CVE-2022-38463
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
Servicenow
Mitigation only
MEDIUM 5.3
CVE-2021-45901EPSS 14%
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exist…
Servicenow
No fix yet
MEDIUM 5.4
CVE-2019-20768
ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_…
It Service Management
No fix yet
HIGH 8.8
CVE-2018-7748
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…
Servicenow
No fix yet
MEDIUM 5.4
CVE-2018-8720
ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search bar of My Portal (aka search_r…
It Service Management
No fix yet