| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-24801 🧪 | GLPI allows authenticated remote code execution EPSS 0.20 | glpi-project | glpi | High | 8.5 | 2025-03-18 18:32:06 | Deep Dive |
| CVE-2025-24799 🧪 💣 | GLPI allows unauthenticated SQL injection through the inventory endpoint EPSS 0.86 | glpi-project | glpi | High | 7.5 | 2025-03-18 18:27:55 | Deep Dive |
| CVE-2025-21619 | GLPI allows SQL injection through the rules configuration | glpi-project | glpi | 中危 | - | 2025-03-18 18:25:13 | Deep Dive |
| CVE-2025-26626 | GLPI Inventory Plugin vulnerable to reflective Cross-site Scripting | glpi-project | glpi-inventory-plugin | Medium | 6.5 | 2025-03-14 12:47:14 | Deep Dive |
| CVE-2025-25192 | GLPI allows unauthorized access to debug mode | glpi-project | glpi | Medium | 6.5 | 2025-02-25 17:58:20 | Deep Dive |
| CVE-2025-23046 | GLPI vulnerable to unauthorized authentication by email using the OAuthIMAP plugin | glpi-project | glpi | 中危 | - | 2025-02-25 17:48:18 | Deep Dive |
| CVE-2025-23024 | GLPI: Plugins are disabled accessing one page | glpi-project | glpi | 中危 | - | 2025-02-25 15:47:33 | Deep Dive |
| CVE-2025-21627 | GLPI Cross-site Scripting vulnerability | glpi-project | glpi | Medium | 6.5 | 2025-02-25 15:43:35 | Deep Dive |
| CVE-2025-21626 | GLPI vulnerable to exposure of sensitive information in the `status.php` endpoint | glpi-project | glpi | Medium | 5.8 | 2025-02-25 15:37:28 | Deep Dive |
| CVE-2024-11955 | GLPI index.php redirect | - | GLPI | Medium | 4.3 | 2025-02-25 15:07:57 | Deep Dive |
| CVE-2024-50339 | GLPI vulnerable to unauthenticated session hijacking EPSS 0.20 | glpi-project | glpi | 中危 | - | 2024-12-11 17:48:42 | Deep Dive |
| CVE-2024-48912 | GLPI vulnerable to authenticated insecure account deletion | glpi-project | glpi | 中危 | - | 2024-12-11 17:03:10 | Deep Dive |
| CVE-2024-47761 | GLPI vulnerable to account takeover via the password reset feature | glpi-project | glpi | 中危 | - | 2024-12-11 17:00:49 | Deep Dive |
| CVE-2024-47760 | GLPI vulnerable to account takeover via API | glpi-project | glpi | 中危 | - | 2024-12-11 16:56:58 | Deep Dive |
| CVE-2024-47758 | GLPI vulnerable to account takeover without privilege escalation through the API | glpi-project | glpi | 中危 | - | 2024-12-11 15:50:22 | Deep Dive |
| CVE-2024-43416 🧪 | GLPI vulnerable to enumeration of users' email addresses by unauthenticated user | glpi-project | glpi | High | 7.5 | 2024-11-18 16:27:06 | Deep Dive |
| CVE-2024-38370 | GLPI allows API document download without rights | glpi-project | glpi | Medium | 5.3 | 2024-11-15 21:12:57 | Deep Dive |
| CVE-2024-45611 | GLPI has a stored XSS at src/RSSFeed.php | glpi-project | glpi | Medium | 5.7 | 2024-11-15 20:16:18 | Deep Dive |
| CVE-2024-45610 | GLPI has a reflected XSS in ajax/cable.php | glpi-project | glpi | Medium | 6.5 | 2024-11-15 20:14:34 | Deep Dive |
| CVE-2024-45609 | GLPI has a Reflected XSS in /front/stat.graph.php | glpi-project | glpi | Medium | 6.5 | 2024-11-15 20:02:33 | Deep Dive |