Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
239 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Glpi-project Glpi | 15/9/2021 | 17/6/2026 | GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround. | |
| Modificada | Media (5.3) | 4.7% | 💥 Exploit | Glpi-project Glpi | 15/9/2021 | 17/6/2026 | GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI. | |
| Modificada | Media (6.5) | 1.0% | — | Glpi-project Glpi | 15/9/2021 | 17/6/2026 | GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version… | |
| Modificada | Alta (8.8) | 0.53% | — | Glpi-project Glpi | 15/9/2021 | 17/6/2026 | GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in version 9.5.6. There are no workarounds… | |
| Modificada | Media (6.1) | 1.4% | — | Glpi-project Glpi | 26/5/2021 | 17/6/2026 | GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code. | |
| Modificada | Media (4.3) | 0.81% | — | Glpi-project Dashboard | 6/4/2021 | 17/6/2026 | The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing information about the last ten events, the connected users, and the users in the tech category. For example, plugins/dashboard/front/main2.php can be used. | |
| Modificada | Alta (7.5) | 2.3% | — | Glpi-project Glpi | 8/3/2021 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to carry out malicious… | |
| Modificada | Media (6.5) | 1.4% | — | Glpi-project Glpi | 8/3/2021 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 it is possible to create tickets for another user with self-service interface without delegatee systems enabled. This is fixed in version 9.5.4. | |
| Modificada | Media (4.8) | 0.63% | — | Glpi-project Glpi | 8/3/2021 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 a new budget type can be defined by user. This input is not correctly filtered. This results in a cross-site scripting attack. To exploit this… | |
| Modificada | Media (6.5) | 1.4% | — | Glpi-project Glpi | 8/3/2021 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 there is an Insecure Direct Object Reference (IDOR) on "Solutions". This vulnerability gives an unauthorized user the ability to enumerate GLPI… | |
| Modificada | Media (4.8) | 0.59% | — | Glpi-project Glpi | 3/3/2021 | 17/6/2026 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is an XSS vulnerability involving a logged in user while updating a ticket. | |
| Modificada | Media (6.1) | 0.92% | — | Glpi-project Glpi | 3/3/2021 | 17/6/2026 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability in the /ajax/common.tabs.php endpoint, indeed, at least two parameters _target and id are not properly sanitized. Here… | |
| Modificada | Media (4.8) | 0.59% | — | Glpi-project Glpi | 3/3/2021 | 17/6/2026 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package. In GLPI before verison 9.5.4, there is a vulnerability within the document upload function (Home > Management > Documents > Add, or /front/document.form.php endpoint), indeed… | |
| Modificada | Media (5.4) | 0.65% | — | Glpi-project Glpi | 2/3/2021 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI from version 9.5.0 and before version 9.5.4, there is a cross-site scripting injection vulnerability when using ajax/kanban.php. This is fixed in version 9.5.4. | |
| Modificada | Media (5.7) | 0.85% | — | Glpi-project Glpi | 2/3/2021 | 17/6/2026 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI version 9.5.3, it was possible to switch entities with IDOR from a logged in user. This is fixed in version 9.5.4. | |
| Modificada | Media (4.3) | 0.87% | — | Glpi-project Glpi | 26/11/2020 | 17/6/2026 | In GLPI before 9.5.3, ajax/getDropdownValue.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any itemType (e.g., Ticket, Users, etc.). | |
| Modificada | Media (4.3) | 0.69% | — | Glpi-project Glpi | 26/11/2020 | 17/6/2026 | In GLPI before 9.5.3, ajax/comments.php has an Insecure Direct Object Reference (IDOR) vulnerability that allows an attacker to read data from any database table (e.g., glpi_tickets, glpi_users, etc.). | |
| Modificada | Media (6.5) | 1.2% | — | Glpi-project Glpi | 25/11/2020 | 17/6/2026 | GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.3, any authenticated user has read-only permissions to the planning of every other user, even… | |
| Modificada | Media (4.3) | 1.0% | — | Glpi-project Glpi | 7/10/2020 | 17/6/2026 | In GLPI before version 9.5.2, there is a SQL Injection in the API's search function. Not only is it possible to break the SQL syntax, but it is also possible to utilise a UNION SELECT query to reflect sensitive information such as the current database version, or database user. The most likely scenario for this… | |
| Modificada | Media (5.3) | 1.0% | — | Glpi-project Glpi | 7/10/2020 | 17/6/2026 | In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ. | |
| Modificada | Media (6.1) | 0.77% | — | Glpi-project Glpi | 7/10/2020 | 17/6/2026 | In GLPI before version 9.5.2, the `install/install.php` endpoint insecurely stores user input into the database as `url_base` and `url_base_api`. These settings are referenced throughout the application and allow for vulnerabilities like Cross-Site Scripting and Insecure Redirection Since authentication is not… | |
| Modificada | Alta (8.6) | 1.1% | — | Glpi-project Glpi | 7/10/2020 | 17/6/2026 | In GLPI before version 9.5.2, when supplying a back tick in input that gets put into a SQL query,the application does not escape or sanitize allowing for SQL Injection to occur. Leveraging this vulnerability an attacker is able to exfiltrate sensitive information like passwords, reset tokens, personal details, and… | |
| Modificada | Crítica (9.1) | 72% | 💥 PoC | Glpi-project Glpi | 7/10/2020 | 17/6/2026 | In GLPI before version 9.5.2, the `pluginimage.send.php` endpoint allows a user to specify an image from a plugin. The parameters can be maliciously crafted to instead delete the .htaccess file for the files directory. Any user becomes able to read all the files and folders contained in “/files/”. Some of the… | |
| Modificada | Alta (7.5) | 0.33% | — | Glpi-project Glpi | 23/9/2020 | 17/6/2026 | In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption library. The library chosen is sodium. | |
| Modificada | Alta (7.1) | 1.2% | — | Glpi-project Glpi | 17/7/2020 | 17/6/2026 | In glpi before 9.5.1, there is a SQL injection for all usages of "Clone" feature. This has been fixed in 9.5.1. |