| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-34244 | GLPI vulnerable to reflected XSS in search pages | glpi-project | glpi | Medium | 6.5 | 2023-07-05 19:22:08 | Deep Dive |
| CVE-2023-34107 | GLPI vulnerable to unauthorized access to KnowbaseItem data | glpi-project | glpi | Medium | 6.5 | 2023-07-05 19:15:31 | Deep Dive |
| CVE-2023-34106 | GLPI vulnerable to unauthorized access to User data | glpi-project | glpi | Medium | 6.5 | 2023-07-05 17:48:33 | Deep Dive |
| CVE-2023-34254 | Remote inventory task command injection when using ssh command mode | glpi-project | glpi-agent | High | 7.6 | 2023-06-23 20:19:04 | Deep Dive |
| CVE-2023-28852 | GLPI vulnerable to stored Cross-site Scripting through dashboard administration | glpi-project | glpi | Medium | 4.8 | 2023-04-05 17:45:31 | Deep Dive |
| CVE-2023-28849 | GLPI vulnerable to SQL injection and Stored XSS via inventory agent request | glpi-project | glpi | Critical | 10.0 | 2023-04-05 17:41:21 | Deep Dive |
| CVE-2023-28838 | GLPI vulnerable to SQL injection through dynamic reports | glpi-project | glpi | Critical | 9.6 | 2023-04-05 17:39:05 | Deep Dive |
| CVE-2023-28636 | GLPI vulnerable to stored Cross-site Scripting in external links | glpi-project | glpi | Medium | 4.5 | 2023-04-05 17:21:22 | Deep Dive |
| CVE-2023-28634 | GLPI vulnerable to Privilege Escalation from Technician to Super-Admin | glpi-project | glpi | High | 8.8 | 2023-04-05 16:06:11 | Deep Dive |
| CVE-2023-28633 | GLPI vulnerable to Blind Server-Side Request Forgery (SSRF) in RSS feeds | glpi-project | glpi | Low | 3.5 | 2023-04-05 15:27:59 | Deep Dive |
| CVE-2023-28632 | GLPI vulnerable to account takeover by authenticated user | glpi-project | glpi | High | 8.1 | 2023-04-05 14:45:12 | Deep Dive |
| CVE-2023-28639 | GLPI vulnerable to reflected Cross-site Scripting in search pages | glpi | glpi | Medium | 6.1 | 2023-04-05 00:00:00 | Deep Dive |
| CVE-2022-41941 | glpi contains XSS Stored inside Standard Interface Help Link href attribute | glpi-project | glpi | Medium | 6.2 | 2023-01-25 06:06:23 | Deep Dive |
| CVE-2023-22500 | glpi Unauthorized access to inventory files | glpi-project | glpi | High | 7.5 | 2023-01-25 06:03:57 | Deep Dive |
| CVE-2023-22722 | glpi subject to Cross-site Scripting (XSS) - Reflected | glpi-project | glpi | Medium | 6.8 | 2023-01-25 05:58:01 | Deep Dive |
| CVE-2023-22724 | glpi contains XSS in RSS Description Link | glpi-project | glpi | Medium | 6.2 | 2023-01-25 05:55:10 | Deep Dive |
| CVE-2023-22725 | glpi vulnerable to XSS on external links | glpi-project | glpi | Medium | 6.2 | 2023-01-25 05:50:19 | Deep Dive |
| CVE-2023-23610 | glpi vulnerable to Unauthorized access to data export | glpi-project | glpi | Medium | 6.5 | 2023-01-25 05:46:36 | Deep Dive |
| CVE-2022-39181 | GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS) | GLPI | Reports plugin for GLPI | Medium | 6.1 | 2022-11-17 22:27:55 | Deep Dive |
| CVE-2022-39234 | user session persists even after permanently deleting account in GLPI | glpi-project | glpi | Medium | 4.7 | 2022-11-03 00:00:00 | Deep Dive |