Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Help Desk Server HIGH 8.8
CVE-2021-43609

An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket funct…

Fix: 1.3.3+
Fix from $1,950 2023-11-09
Spiceworks MEDIUM 6.1
CVE-2020-25901EPSS 5%

Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host head…

No fix yet
Fix from $1,600 2020-12-18
Spiceworks HIGH 8.8
CVE-2020-23451

Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

Fix: after 7.5.00107
Fix from $1,950 2020-09-15
Spiceworks MEDIUM 5.4
CVE-2020-23450

Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://…

Fix: after 7.5.00107
Fix from $1,600 2020-09-01
Desktop MEDIUM 6.1
CVE-2015-6021

Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.

Fix: after 7.5.00093
Fix from $1,600 2017-04-10
Spiceworks CRITICAL 9.8
CVE-2017-7237EPSS 7%

The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations direct…

No fix yet
Fix from $2,300 2017-04-06
Spiceworks MEDIUM 6.5
CVE-2012-2956

SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v…

No fix yet
Fix from $1,600 2014-09-17