Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-25937 GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malicious actor with knowledge of … Glpi 11.0.6+ Fix from $1,6002026-03-18 HIGH 8.8 CVE-2026-25936 GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an authenticated user can perfom a S… Glpi after 11.0.6 Fix from $1,9502026-03-17 CRITICAL 9.1 CVE-2026-23489 Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to version 1.23.3, it is possible to execute arbitrary PHP … Fields 1.23.3+ Fix from $2,3002026-03-16 HIGH 8.8 CVE-2026-22248 GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. Fr… Glpi 11.0.5+ Fix from $1,9502026-03-11 MEDIUM 5.4 CVE-2023-33971 Formcreator is a GLPI plugin which allow creation of custom forms and the creation of one or more tickets when the form is filled. A probable stored … Form Creator No fix yet Fix from $1,6002023-05-31 MEDIUM 6.5 CVE-2023-28855 Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to versions 1.13.1 and 1.20.4, lack of access control check… Fields 1.13.1 / 1.20.4+ Fix from $1,6002023-04-05 MEDIUM 5.3 CVE-2021-39190 The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is… System Center Configuration Manager 2.3.0+ Fix from $1,6002022-09-22 CRITICAL 9.9 CVE-2021-43779EPSS 9% GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers fro… Addressing 2.9.1+ Fix from $2,3002022-01-05 MEDIUM 6.1 CVE-2019-12724 An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter. News after 1.5.2 Fix from $1,6002019-07-10 CRITICAL 9.8 CVE-2019-12723 An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and old_order parameters to ajax… Fields after 1.9.2 Fix from $2,3002019-07-10 CRITICAL 9.8 CVE-2019-10231 Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occurs in Auth::checkPassword() (… Gestionnaire Libre De Parc Informatique 9.4.1.1+ Fix from $2,3002019-03-27 CRITICAL 9.8 CVE-2019-10232EPSS 23% Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php. Gestionnaire Libre De Parc Informatique after 9.3.3 Fix from $2,3002019-03-27