| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-45608 | GLPI has an Authenticated SQL Injection | glpi-project | glpi | Medium | 6.5 | 2024-11-15 18:24:48 | Deep Dive |
| CVE-2024-43418 | GLPI has multiple reflected XSS | glpi-project | glpi | Medium | 6.5 | 2024-11-15 18:23:32 | Deep Dive |
| CVE-2024-43417 | Reflected XSS in Software form | glpi-project | glpi | Medium | 6.5 | 2024-11-15 18:22:04 | Deep Dive |
| CVE-2024-41679 | Authenticated SQL injection in ticket form | glpi-project | glpi | Medium | 6.5 | 2024-11-15 18:20:44 | Deep Dive |
| CVE-2024-41678 | GLPI has multiple reflected XSS | glpi-project | glpi | Medium | 6.5 | 2024-11-15 18:08:47 | Deep Dive |
| CVE-2024-40638🧪 | GLPI allows account takeover via SQL Injection in AJAX scripts EPSS 0.37 | glpi-project | glpi | High | 8.1 | 2024-11-15 18:06:37 | Deep Dive |
| CVE-2024-47759 | GLPI has a stored XSS via document upload | glpi-project | glpi | - | - | 2024-11-15 17:42:01 | Deep Dive |
| CVE-2024-37149🧪 | GLPI allows remote code execution through the plugin loader EPSS 0.21 | glpi-project | glpi | High | 7.2 | 2024-07-10 19:20:36 | Deep Dive |
| CVE-2024-37148🧪 | GLPI allows account takeover via SQL Injection in AJAX scripts EPSS 0.20 | glpi-project | glpi | High | 8.1 | 2024-07-10 19:18:09 | Deep Dive |
| CVE-2024-37147📌 | GLPI allows Authenticated File Upload to Restricted Tickets | glpi-project | glpi | Medium | 4.3 | 2024-07-10 18:38:38 | Deep Dive |
| CVE-2024-31456🧪 | GLPI contains an authenticated SQL injection EPSS 0.59 | glpi-project | glpi | High | 7.7 | 2024-05-07 14:07:08 | Deep Dive |
| CVE-2024-29889🧪💣 | GLPI contains an SQL injection through the saved searches EPSS 0.63 | glpi-project | glpi | High | 7.1 | 2024-05-07 14:05:32 | Deep Dive |
| CVE-2024-28241🧪 | GlPI-Agent MSI package installation doesn't update folder security profile when using non default installation folder | glpi-project | glpi-agent | High | 7.3 | 2024-04-25 16:44:52 | Deep Dive |
| CVE-2024-28240🧪 | GLPI-Agent's MSI package installation permits local users to change Agent configuration | glpi-project | glpi-agent | High | 7.3 | 2024-04-25 16:37:32 | Deep Dive |
| CVE-2024-27914📌 | Reflected Cross-Site Scripting (XSS) in search engine when debug mode is enabled in GLPI | glpi-project | glpi | Medium | 5.3 | 2024-03-18 16:19:00 | Deep Dive |
| CVE-2024-27104 | Stored XSS in dashboards in GLPI | glpi-project | glpi | Medium | 4.5 | 2024-03-18 16:16:39 | Deep Dive |
| CVE-2024-27098 | Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPI EPSS 0.36 | glpi-project | glpi | Medium | 6.4 | 2024-03-18 16:14:19 | Deep Dive |
| CVE-2024-27096🧪 | SQL Injection in through the search engine EPSS 0.59 | glpi-project | glpi | High | 7.7 | 2024-03-18 16:11:08 | Deep Dive |
| CVE-2024-27930 | Sensitive fields access through dropdowns in GLPI | glpi-project | glpi | Medium | 6.5 | 2024-03-18 15:29:11 | Deep Dive |
| CVE-2024-27937 | glpi Users emails enumeration EPSS 0.27 | glpi-project | glpi | Medium | 6.5 | 2024-03-18 15:17:18 | Deep Dive |