Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2021-43609
An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket funct…
Help Desk Server
1.3.3+
MEDIUM 6.1
CVE-2020-25901EPSS 5%
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host head…
Spiceworks
No fix yet
HIGH 8.8
CVE-2020-23451
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
Spiceworks
after 7.5.00107
MEDIUM 5.4
CVE-2020-23450
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://…
Spiceworks
after 7.5.00107
MEDIUM 6.1
CVE-2015-6021
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
Desktop
after 7.5.00093
CRITICAL 9.8
CVE-2017-7237EPSS 7%
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations direct…
Spiceworks
No fix yet
MEDIUM 6.5
CVE-2012-2956
SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v…
Spiceworks
No fix yet