Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
239 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | Glpi-project Glpi | 12/5/2020 | 17/6/2026 | In GLPI after 0.68.1 and before 9.4.6, multiple reflexive XSS occur in Dropdown endpoints due to an invalid Content-Type. This has been fixed in version 9.4.6. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | Glpi-project Glpi | 12/5/2020 | 17/6/2026 | In GLPI before 9.4.6, an attacker can execute system commands by abusing the backup functionality. Theoretically, this vulnerability can be exploited by an attacker without a valid account by using a CSRF. Due to the difficulty of the exploitation, the attack is only conceivable by an account having Maintenance… | |
| Modificada | Media (5.3) | 1.5% | 💥 PoC | Glpi-project Glpi | 12/5/2020 | 17/6/2026 | GLPI before before version 9.4.6 has a vulnerability involving a default encryption key. GLPIKEY is public and is used on every instance. This means anyone can decrypt sensitive data stored using this key. It is possible to change the key before installing GLPI. But on existing instances, data must be reencrypted with… | |
| Modificada | Media (5.4) | 0.80% | — | Glpi-project Glpi | 5/5/2020 | 17/6/2026 | In GLPI before version 9.4.6 there are multiple related stored XSS vulnerabilities. The package is vulnerable to Stored XSS in the comments of items in the Knowledge base. Adding a comment with content "<script>alert(1)</script>" reproduces the attack. This can be exploited by a user with administrator privileges in… | |
| Modificada | Crítica (9.3) | 0.80% | — | Glpi-project GlpiFedoraproject Fedora | 5/5/2020 | 17/6/2026 | In GLPI after version 0.83.3 and before version 9.4.6, the CSRF tokens are generated using an insecure algorithm. The implementation uses rand and uniqid and MD5 which does not provide secure values. This is fixed in version 9.4.6. | |
| Modificada | Media (6.1) | 7.6% | 💥 Exploit | Glpi-project Glpi | 5/5/2020 | 17/6/2026 | In GLPI before version 9.4.6, there is a vulnerability that allows bypassing the open redirect protection based which is based on a regexp. This is fixed in version 9.4.6. | |
| Modificada | Alta (7.2) | 1.0% | — | Glpi-project GlpiFedoraproject Fedora | 5/5/2020 | 17/6/2026 | In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalations or read/update/delete data normally non accessible to the… | |
| Modificada | Alta (7.2) | 1.0% | — | Glpi-project Glpi | 5/5/2020 | 17/6/2026 | In GLPI before version 9.4.6, there is a SQL injection vulnerability for all helpdesk instances. Exploiting this vulnerability requires a technician account. This is fixed in version 9.4.6. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Glpi-project GlpiDebian Linux | 1/11/2019 | 16/6/2026 | GLPI 0.83.7 has Local File Inclusion in common.tabs.php. | |
| Modificada | Alta (8.8) | 2.2% | — | Glpi-project Glpi | 25/9/2019 | 17/6/2026 | GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack of correct validation leads to recovery of the token generated via the password reset functionality, and thus an authenticated attacker can set an arbitrary password for any user. This vulnerability… | |
| Modificada | Media (5.4) | 0.76% | — | Glpi-project Glpi | 15/7/2019 | 17/6/2026 | GLPI GLPI Product 9.3.1 is affected by: Cross Site Scripting (XSS). The impact is: All dropdown values are vulnerable to XSS leading to privilege escalation and executing js on admin. The component is: /glpi/ajax/getDropDownValue.php. The attack vector is: 1- User Create a ticket , 2- Admin opens another ticket and… | |
| Modificada | Baja (3.5) | 0.72% | — | Glpi-project Glpi | 12/7/2019 | 17/6/2026 | GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tools > Reminder > Description .. Set the description to any… | |
| Modificada | Media (5.9) | 1.7% | — | Glpi-project Glpi | 10/7/2019 | 17/6/2026 | An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that user's password again during the next 24 hours without any information except the associated email address. | |
| Modificada | Media (6.1) | 1.3% | — | Glpi-project Glpi | 4/7/2019 | 17/6/2026 | inc/user.class.php in GLPI before 9.4.3 allows XSS via a user picture. | |
| Modificada | Crítica (9.8) | 1.5% | — | Glpi Dashboard Project Glpi Dashboard | 2/6/2019 | 17/6/2026 | Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue.php, load.php, mem.php, traf.php, and uptime.php in front/sh. | |
| Modificada | Alta (8.1) | 1.4% | — | Glpi-project Glpi | 27/3/2019 | 17/6/2026 | Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie. | |
| Modificada | Alta (8.8) | 1.2% | — | Glpi-project Glpi | 2/7/2018 | 17/6/2026 | The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php. | |
| Modificada | Media (6.1) | 1.1% | — | Glpi-project Glpi | 12/3/2018 | 17/6/2026 | An issue was discovered in GLPI through 9.2.1. The application is affected by XSS in the query string to front/preference.php. An attacker is able to create a malicious URL that, if opened by an authenticated user with debug privilege, will execute JavaScript code supplied by the attacker. The attacker-supplied code… | |
| Modificada | Alta (7.5) | 1.7% | — | Glpi-project Glpi | 12/3/2018 | 17/6/2026 | A remote code execution issue was discovered in GLPI through 9.2.1. There is a race condition that allows temporary access to an uploaded executable file that will be disallowed. The application allows an authenticated user to upload a file when he/she creates a new ticket via front/fileupload.php. This feature is… | |
| Modificada | Crítica (9.8) | 1.6% | — | Glpi-project Glpi | 28/7/2017 | 17/6/2026 | SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter. | |
| Modificada | Media (4.9) | 1.3% | — | Glpi-project Glpi | 28/7/2017 | 17/6/2026 | front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Glpi-project Glpi | 20/7/2017 | 17/6/2026 | GLPI before 9.1.5.1 has SQL Injection in the condition rule field, exploitable via front/rulesengine.test.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Glpi-project Glpi | 20/7/2017 | 17/6/2026 | GLPI before 9.1.5.1 has SQL Injection in the $crit variable in inc/computer_softwareversion.class.php, exploitable via ajax/common.tabs.php. | |
| Modificada | Media (5.4) | 0.64% | — | Glpi-project Glpi | 19/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket. | |
| Modificada | Alta (8) | 0.49% | — | Glpi-project Glpi | 19/7/2017 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request that could lead to the creation of an admin account in the application. |