Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2025-2776 KEVEPSS 64%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function…
Sysaid
after 23.3.40
CRITICAL 9.8
CVE-2025-2777EPSS 72%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,…
Sysaid
after 23.3.40
HIGH 7.5
CVE-2025-2775 KEVEPSS 43%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali…
Sysaid
after 23.3.40
CRITICAL 9.8
CVE-2024-36393
SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Sysaid
after 23.3.38
CRITICAL 9.8
CVE-2024-36394
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Sysaid
after 23.3.38
MEDIUM 6.5
CVE-2023-33706
SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp o…
Sysaid
23.2.15 / 23.2.50+
CRITICAL 9.8
CVE-2023-47246 KEVEPSS 99%
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as…
Sysaid
23.3.36+
MEDIUM 6.5
CVE-2023-32226
Sysaid - CWE-552: Files or Directories Accessible to External Parties -
Authenticated users may exfiltrate files from the server via an unspecifie…
Sysaid On Premises
23.2.14+
HIGH 7.2
CVE-2023-32225
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -
A malicious user with administrative privileges may be able to upload a dangero…
Sysaid On Premises
23.2.14+
MEDIUM 6.1
CVE-2022-40322
SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.
Help Desk
22.1.65+
MEDIUM 6.1
CVE-2022-40323
SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.
Help Desk
22.1.65+
MEDIUM 6.1
CVE-2022-40324
SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.
Help Desk
22.1.65+
MEDIUM 6.1
CVE-2022-40325
SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.
Help Desk
22.1.65+
CRITICAL 9.8
CVE-2022-23170
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO in…
Okta Sso
after 22.1.63
CRITICAL 9.8
CVE-2022-23166
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" …
Sysaid
22.1.64 / 22.2.20+
MEDIUM 6.1
CVE-2022-23165
Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treecontent.jsp" suffers from a Re…
Sysaid
22.1.64 / 22.2.20+
CRITICAL 9.8
CVE-2022-22796
Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, t…
Sysaid
21.1.30 / 21.4.45+
HIGH 8.8
CVE-2022-22798
Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest a…
Sysaid
21.1.50 / 22.1.64+
MEDIUM 6.1
CVE-2022-22797
Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /Com…
Sysaid
22.1.50 / 22.1.64+
HIGH 8.8
CVE-2021-43971
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL c…
Sysaid
No fix yet
HIGH 8.8
CVE-2021-43973
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitra…
Sysaid
Patch available
MEDIUM 6.5
CVE-2021-43972
An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arb…
Sysaid
Patch available
MEDIUM 5.3
CVE-2021-43974
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the serv…
Itil
No fix yet
MEDIUM 5.3
CVE-2021-36721
Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names f…
Application Programming Interface
21.3.60+
MEDIUM 6.1
CVE-2021-31862
SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.
Sysaid
No fix yet
HIGH 8.8
CVE-2021-30486
SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group…
Sysaid
No fix yet
MEDIUM 6.1
CVE-2021-30049
SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.
Sysaid
No fix yet
MEDIUM 6.1
CVE-2020-13168
SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.
Sysaid On Premises
No fix yet
CRITICAL 9.8
CVE-2020-10569
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticate…
On Premise
No fix yet
MEDIUM 5.0
CVE-2015-3001EPSS 7%
SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated use…
Sysaid
after 15.1