Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Snipe It MEDIUM 6.5
CVE-2026-55469

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated user with import and assets.update permissions can place a path t…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 5.7
CVE-2026-55475

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, the Importer API endpoint allows a user with CSV import capabilities and a valid A…

Fix: 8.6.1+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 5.0
CVE-2026-55515

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the unaccepted-assets report delete endpoint authorizes only reports.view and dele…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Snipe It HIGH 8.7
CVE-2026-55466

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP finfo reports image/svg+xml …

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Snipe It HIGH 7.3
CVE-2026-55452

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent header and ReportsController:…

Fix: 8.5.0+
Fix from $1,950 2026-07-10
Snipe It MEDIUM 6.1
CVE-2026-55461

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the user edit flow stores url()->previous() from the attacker-controlled Referer h…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 6.5
CVE-2026-55843

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through Normal…

Fix: 8.6.0+
Fix from $1,600 2026-07-10
Snipe It HIGH 7.7
CVE-2026-55516

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current ma…

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Snipe It MEDIUM 6.5
CVE-2026-55474

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route filename parameter into a p…

Fix: 8.5.0+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 5.4
CVE-2026-55478

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but do…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Snipe It HIGH 7.7
CVE-2026-54329

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request parameters to the Accessory m…

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Snipe It HIGH 7.1
CVE-2026-55460

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, an authenticated non-admin user with users.view and users.edit but without users.d…

Fix: 8.6.2+
Fix from $1,950 2026-07-10
Snipe It MEDIUM 5.4
CVE-2026-55464

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, CommonMark escapes raw HTML but does not sanitize javascript: URIs in Markdown hyp…

Fix: 8.6.2+
Fix from $1,600 2026-07-10
Snipe It MEDIUM 6.5
CVE-2026-48492

Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, the GET /api/v1/{object}/selectlist API endpoint is missing an authorizati…

Fix: 8.6.0+
Fix from $1,600 2026-07-08
Snipe It MEDIUM 5.5
CVE-2026-48493

Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_o…

Fix: 8.6.0+
Fix from $1,600 2026-06-23
Snipe It HIGH 7.1
CVE-2026-48507

Snipe-IT is an IT asset/license management system. A vulnerability in versions prior to 8.6.0 allows a non-admin user holding only the granular `user…

Fix: 8.6.0+
Fix from $1,950 2026-06-08
Snipe It HIGH 8.8
CVE-2026-44832

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own priv…

Fix: 8.4.1+
Fix from $1,950 2026-05-26
Snipe It HIGH 7.1
CVE-2026-44833

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to m…

Fix: 8.4.1+
Fix from $1,950 2026-05-26
Snipe It MEDIUM 5.4
CVE-2026-44831

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, r…

Fix: 8.4.1+
Fix from $1,600 2026-05-26
Snipe It CRITICAL 9.8
CVE-2026-37709

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to …

Fix: 8.4.1+
Fix from $2,300 2026-05-07
Snipe It MEDIUM 6.5
CVE-2026-38533

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit perm…

No fix yet
Fix from $1,600 2026-04-14
Snipe It HIGH 8.8
CVE-2025-15602

Snipe-IT versions prior to 8.3.7 contain sensitive user attributes related to account privileges that are insufficiently protected against mass assig…

Fix: 8.3.7+
Fix from $1,950 2026-03-06
Snipe It MEDIUM 5.4
CVE-2025-65622

Snipe-IT before 8.3.4 allows stored XSS via the Locations "Country" field, enabling a low-privileged authenticated user to inject JavaScript that exe…

Fix: 8.3.4+
Fix from $1,600 2025-12-01
Snipe It MEDIUM 5.4
CVE-2025-65621

Snipe-IT before 8.3.4 allows stored XSS, allowing a low-privileged authenticated user to inject JavaScript that executes in an administrator's sessio…

Fix: 8.3.4+
Fix from $1,600 2025-12-01
Snipe It MEDIUM 6.1
CVE-2025-64027

Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. When an invalid CSV file is u…

No fix yet
Fix from $1,600 2025-11-20
Snipe It CRITICAL 9.9
CVE-2025-63601

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious backup file …

Fix: 8.3.3+
Fix from $2,300 2025-11-05
Snipe It HIGH 8.1
CVE-2025-59713

Snipe-IT before 8.1.18 allows unsafe deserialization.

Fix: 8.1.18+
Fix from $1,950 2025-09-19
Snipe It MEDIUM 5.4
CVE-2025-59712

Snipe-IT before 8.1.18 allows XSS.

Fix: 8.1.18+
Fix from $1,600 2025-09-19
Snipe It HIGH 8.7
CVE-2024-51093

Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. T…

Mitigation only
Fix from $1,950 2024-11-12
Snipe It HIGH 8.0
CVE-2024-51094

An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name…

Mitigation only
Fix from $1,950 2024-11-12