| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-35945 | Cross site scripting (XSS) via registration API in GLPI | glpi-project | glpi | Medium | 6.3 | 2022-09-14 17:45:12 | Deep Dive |
| CVE-2022-31143 | Leak of sensitive information through login page error in GLPI | glpi-project | glpi | Medium | 5.3 | 2022-09-14 17:40:09 | Deep Dive |
| CVE-2022-31061 | SQL injection on login page in GLPI | glpi-project | glpi | Critical | 9.8 | 2022-06-28 17:55:11 | Deep Dive |
| CVE-2022-31068 | Sensitive Data Exposure on Refused Inventory Files in GLPI | glpi-project | glpi | Medium | 5.3 | 2022-06-28 17:50:11 | Deep Dive |
| CVE-2022-31056 | SQL injection with _actor parameter in GLPI | glpi-project | glpi | Critical | 9.8 | 2022-06-28 00:00:00 | Deep Dive |
| CVE-2022-31082 | SQL Injection via package deployment tasks in glpi-inventory-plugin | glpi-project | glpi-inventory-plugin | Medium | 5.8 | 2022-06-27 20:30:22 | Deep Dive |
| CVE-2022-31062 | Unauthenticated Local File Inclusion | glpi-project | glpi-inventory-plugin | Medium | 5.3 | 2022-06-20 00:00:00 | Deep Dive |
| CVE-2022-29250 | SQL injection in GLPI | glpi-project | glpi | High | 8.1 | 2022-06-09 19:55:12 | Deep Dive |
| CVE-2022-24876 | Stored cross site scrpting in GLPI's Kanban | glpi-project | glpi | Medium | 5.4 | 2022-06-09 18:50:25 | Deep Dive |
| CVE-2022-24869 | Cross Site Scripting in GLPI | glpi-project | glpi | Medium | 4.6 | 2022-04-21 17:00:16 | Deep Dive |
| CVE-2022-24868 | Cross site scripting via SVG file upload in GLPI | glpi-project | glpi | High | 7.3 | 2022-04-21 16:55:11 | Deep Dive |
| CVE-2022-24867 | LDAP password exposure in glpi | glpi-project | glpi | High | 7.5 | 2022-04-21 16:50:11 | Deep Dive |
| CVE-2021-39213 | IP restriction on GLPI API Bypass with custom header injection | glpi-project | glpi | Medium | 6.8 | 2021-09-15 17:05:09 | Deep Dive |
| CVE-2021-39211 | Disclosure of GLPI and server information in telemetry endpoint | glpi-project | glpi | Medium | 5.3 | 2021-09-15 16:55:10 | Deep Dive |
| CVE-2021-39210 | Autologin cookie accessible by scripts | glpi-project | glpi | Medium | 6.5 | 2021-09-15 16:40:11 | Deep Dive |
| CVE-2021-39209 | Bypassable CSRF protection | glpi-project | glpi | High | 8.8 | 2021-09-15 15:50:10 | Deep Dive |
| CVE-2021-21324 | Insecure Direct Object Reference (IDOR) on "Solutions" | glpi-project | glpi | Medium | 6.8 | 2021-03-08 17:00:33 | Deep Dive |
| CVE-2021-21325 | Stored XSS in budget type | glpi-project | glpi | Medium | 6.2 | 2021-03-08 17:00:27 | Deep Dive |
| CVE-2021-21326 | Horizontal Privilege Escalation | glpi-project | glpi | High | 7.7 | 2021-03-08 17:00:22 | Deep Dive |
| CVE-2021-21327 | Unsafe Reflection in getItemForItemtype() | glpi-project | glpi | Medium | 6.8 | 2021-03-08 17:00:17 | Deep Dive |