Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Servicenow HIGH 7.5
CVE-2024-8924

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthentica…

Mitigation only
Fix from $1,950 2024-10-29
Servicenow CRITICAL 10.0
CVE-2024-8923

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticate…

Mitigation only
Fix from $2,300 2024-10-29
Servicenow CRITICAL 9.8
CVE-2024-4879 KEVEPSS 100%

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerabili…

Mitigation only
Fix from $2,300 2024-07-10
Servicenow CRITICAL 9.8
CVE-2024-5217 KEVEPSS 100%

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. Th…

Mitigation only
Fix from $2,300 2024-07-10
Servicenow MEDIUM 6.1
CVE-2023-1298

ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow …

Mitigation only
Fix from $1,600 2023-07-06
Servicenow MEDIUM 6.5
CVE-2022-43684

ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional…

No fix yet
Fix from $1,600 2023-06-13
Servicenow MEDIUM 5.4
CVE-2023-1209

Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.

Mitigation only
Fix from $1,600 2023-05-23
Servicenow MEDIUM 6.1
CVE-2022-46389

There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, S…

Mitigation only
Fix from $1,600 2023-04-17
Servicenow MEDIUM 6.1
CVE-2022-46886

There exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrary domai…

Mitigation only
Fix from $1,600 2023-04-14
Servicenow MEDIUM 6.1
CVE-2022-39048

A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade a…

Mitigation only
Fix from $1,600 2023-04-10
Servicenow MEDIUM 6.1
CVE-2022-38172

ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performance Analytics dashboard.

Mitigation only
Fix from $1,600 2022-08-23
Servicenow MEDIUM 6.1
CVE-2022-38463

ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.

Mitigation only
Fix from $1,600 2022-08-23
Servicenow MEDIUM 5.3
CVE-2021-45901EPSS 14%

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exist…

No fix yet
Fix from $1,600 2022-02-10
It Service Management MEDIUM 5.4
CVE-2019-20768

ServiceNow IT Service Management Kingston through Patch 14-1, London through Patch 7, and Madrid before patch 4 allow stored XSS via crafted sysparm_…

No fix yet
Fix from $1,600 2020-05-05
Servicenow HIGH 8.8
CVE-2018-7748

report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Inj…

No fix yet
Fix from $1,950 2018-08-03
It Service Management MEDIUM 5.4
CVE-2018-8720

ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search bar of My Portal (aka search_r…

No fix yet
Fix from $1,600 2018-03-15