Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.6 CVE-2024-48987 Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by… Snipe It 7.0.10+ Fix from $1,6002024-10-11 HIGH 8.1 CVE-2024-5685 Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships vi… Snipe It 6.4.2+ Fix from $1,9502024-06-14 HIGH 8.8 CVE-2023-5511 Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3. Snipe It 6.2.3+ Fix from $1,9502023-10-11 MEDIUM 5.4 CVE-2023-5452 Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2. Snipe It 6.2.2+ Fix from $1,6002023-10-06 MEDIUM 5.3 CVE-2022-44381 Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request. Snipe It after 6.0.14 Fix from $1,6002022-12-25 MEDIUM 5.4 CVE-2022-44380 Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets. Snipe It 6.0.14+ Fix from $1,6002022-12-25 HIGH 8.0 CVE-2022-2997 Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10. Snipe It 6.0.10+ Fix from $1,9502022-08-25 HIGH 8.8 CVE-2022-23064 In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password … Snipe It after 5.3.7 Fix from $1,9502022-05-02 MEDIUM 6.5 CVE-2022-1511 Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4. Snipe It 5.4.4+ Fix from $1,6002022-04-28 MEDIUM 5.4 CVE-2022-1445 Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is ca… Snipe It 5.4.3+ Fix from $1,6002022-04-24 MEDIUM 5.4 CVE-2022-1380 Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of… Snipe It 5.4.3+ Fix from $1,6002022-04-16 HIGH 7.4 CVE-2022-1155 Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10. Snipe It 5.3.10+ Fix from $1,9502022-03-30 MEDIUM 5.3 CVE-2022-0622 Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11. Snipe It after 5.3.10 Fix from $1,6002022-02-17 HIGH 8.8 CVE-2022-0611 Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11. Snipe It 5.3.11+ Fix from $1,9502022-02-16 MEDIUM 6.5 CVE-2022-0579 Missing Authorization in Packagist snipe/snipe-it prior to 5.3.9. Snipe It 5.3.9+ Fix from $1,6002022-02-14 MEDIUM 5.4 CVE-2022-0178 Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8. Snipe It 5.3.8+ Fix from $1,6002022-01-13 MEDIUM 5.4 CVE-2022-0179 snipe-it is vulnerable to Missing Authorization Snipe It 5.3.7+ Fix from $1,6002022-01-12 HIGH 8.8 CVE-2021-4130 snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) Snipe It 5.3.6+ Fix from $1,9502021-12-18 MEDIUM 6.1 CVE-2021-4108 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Snipe It 5.3.5+ Fix from $1,6002021-12-14 HIGH 7.2 CVE-2021-4075 snipe-it is vulnerable to Server-Side Request Forgery (SSRF) Snipe It Patch available Fix from $1,9502021-12-06 MEDIUM 5.4 CVE-2021-4018 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Snipe It 5.3.3+ Fix from $1,6002021-12-01 MEDIUM 5.4 CVE-2021-3961 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Snipe It 5.3.2+ Fix from $1,6002021-11-19 MEDIUM 5.4 CVE-2021-3938 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Snipe It after 5.3.1 Fix from $1,6002021-11-13 HIGH 8.8 CVE-2021-3858 snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) Snipe It 5.3.0+ Fix from $1,9502021-10-19 MEDIUM 6.1 CVE-2021-3863 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Snipe It 5.3.0+ Fix from $1,6002021-10-19 MEDIUM 5.4 CVE-2021-3879 snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Snipe It 5.3.0+ Fix from $1,6002021-10-19 MEDIUM 6.1 CVE-2019-10118 Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API. Snipe It 4.6.14+ Fix from $1,6002019-03-27