Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sysaid CRITICAL 9.8
CVE-2025-2776 KEVEPSS 64%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function…

Fix: after 23.3.40
Fix from $2,300 2025-05-07
Sysaid CRITICAL 9.8
CVE-2025-2777EPSS 72%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,…

Fix: after 23.3.40
Fix from $2,300 2025-05-07
Sysaid HIGH 7.5
CVE-2025-2775 KEVEPSS 43%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali…

Fix: after 23.3.40
Fix from $1,950 2025-05-07
Sysaid CRITICAL 9.8
CVE-2024-36393

SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Fix: after 23.3.38
Fix from $2,300 2024-06-06
Sysaid CRITICAL 9.8
CVE-2024-36394

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Fix: after 23.3.38
Fix from $2,300 2024-06-06
Sysaid MEDIUM 6.5
CVE-2023-33706

SysAid before 23.2.15 allows Indirect Object Reference (IDOR) attacks to read ticket data via a modified sid parameter to EmailHtmlSourceIframe.jsp o…

Fix: 23.2.15 / 23.2.50+
Fix from $1,600 2023-11-24
Sysaid CRITICAL 9.8
CVE-2023-47246 KEVEPSS 99%

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as…

Fix: 23.3.36+
Fix from $2,300 2023-11-10
Sysaid On Premises MEDIUM 6.5
CVE-2023-32226

Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files from the server via an unspecifie…

Fix: 23.2.14+
Fix from $1,600 2023-07-30
Sysaid On Premises HIGH 7.2
CVE-2023-32225

Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangero…

Fix: 23.2.14+
Fix from $1,950 2023-07-30
Help Desk MEDIUM 6.1
CVE-2022-40322

SysAid Help Desk before 22.1.65 allows XSS, aka FR# 66542 and 65579.

Fix: 22.1.65+
Fix from $1,600 2022-09-11
Help Desk MEDIUM 6.1
CVE-2022-40323

SysAid Help Desk before 22.1.65 allows XSS in the Password Services module, aka FR# 67241.

Fix: 22.1.65+
Fix from $1,600 2022-09-11
Help Desk MEDIUM 6.1
CVE-2022-40324

SysAid Help Desk before 22.1.65 allows XSS via the Linked SRs field, aka FR# 67258.

Fix: 22.1.65+
Fix from $1,600 2022-09-11
Help Desk MEDIUM 6.1
CVE-2022-40325

SysAid Help Desk before 22.1.65 allows XSS via the Asset Dashboard, aka FR# 67262.

Fix: 22.1.65+
Fix from $1,600 2022-09-11
Okta Sso CRITICAL 9.8
CVE-2022-23170

SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO in…

Fix: after 22.1.63
Fix from $2,300 2022-06-24
Sysaid CRITICAL 9.8
CVE-2022-23166

Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" …

Fix: 22.1.64 / 22.2.20+
Fix from $2,300 2022-05-12
Sysaid MEDIUM 6.1
CVE-2022-23165

Sysaid – Sysaid 14.2.0 Reflected Cross-Site Scripting (XSS) - The parameter "helpPageName" used by the page "/help/treecontent.jsp" suffers from a Re…

Fix: 22.1.64 / 22.2.20+
Fix from $1,600 2022-05-12
Sysaid CRITICAL 9.8
CVE-2022-22796

Sysaid – Sysaid System Takeover - An attacker can bypass the authentication process by accessing to: /wmiwizard.jsp, Then to: /ConcurrentLogin.jsp, t…

Fix: 21.1.30 / 21.4.45+
Fix from $2,300 2022-05-12
Sysaid HIGH 8.8
CVE-2022-22798

Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22.1.30 b49 - An attacker needs to log in as a guest a…

Fix: 21.1.50 / 22.1.64+
Fix from $1,950 2022-05-12
Sysaid MEDIUM 6.1
CVE-2022-22797

Sysaid – sysaid Open Redirect - An Attacker can change the redirect link at the parameter "redirectURL" from"GET" request from the url location: /Com…

Fix: 22.1.50 / 22.1.64+
Fix from $1,600 2022-05-12
Sysaid HIGH 8.8
CVE-2021-43971

A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL c…

No fix yet
Fix from $1,950 2022-01-11
Sysaid HIGH 8.8
CVE-2021-43973

An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitra…

Patch available
Fix from $1,950 2022-01-11
Sysaid MEDIUM 6.5
CVE-2021-43972

An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arb…

Patch available
Fix from $1,600 2022-01-11
Itil MEDIUM 5.3
CVE-2021-43974

An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the serv…

No fix yet
Fix from $1,600 2022-01-11
Application Programming Interface MEDIUM 5.3
CVE-2021-36721

Sysaid API User Enumeration - Attacker sending requests to specific api path without any authorization before 21.3.60 version could get users names f…

Fix: 21.3.60+
Fix from $1,600 2021-12-14
Sysaid MEDIUM 6.1
CVE-2021-31862

SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parameter without any authentication.

No fix yet
Fix from $1,600 2021-10-29
Sysaid HIGH 8.8
CVE-2021-30486

SysAid 20.3.64 b14 is affected by Blind and Stacker SQL injection via AssetManagementChart.jsp (GET computerID), AssetManagementChart.jsp (POST group…

No fix yet
Fix from $1,950 2021-07-22
Sysaid MEDIUM 6.1
CVE-2021-30049

SysAid 20.3.64 b14 is affected by Cross Site Scripting (XSS) via a /KeepAlive.jsp?stamp= URI.

No fix yet
Fix from $1,600 2021-07-22
Sysaid On Premises MEDIUM 6.1
CVE-2020-13168

SysAid 20.1.11b26 allows reflected XSS via the ForgotPassword.jsp accountid parameter.

No fix yet
Fix from $1,600 2020-10-02
On Premise CRITICAL 9.8
CVE-2020-10569

SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticate…

No fix yet
Fix from $2,300 2020-04-21
Sysaid MEDIUM 5.0
CVE-2015-3001EPSS 7%

SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which allows remote authenticated use…

Fix: after 15.1
Fix from $1,600 2015-06-08