Skip to content
Noroxi

spiceworks records

9 published records for vendor spiceworks.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

9 records
  • The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configuratio

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    spiceworks · spiceworksApr 6, 2017

  • An issue was discovered in Spiceworks Help Desk Server before 1.3.3.

    HighCVSS 8.8Proof of conceptEPSS 2%

    spiceworks · help desk serverNov 8, 2023

  • Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

    HighCVSS 8.8No exploitEPSS 1%

    spiceworks · spiceworksSep 15, 2020

  • Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned

    MediumCVSS 6.1Proof of conceptEPSS 5%

    spiceworks · spiceworksDec 18, 2020

  • CVE-2012-2956
    26Monitor

    SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter

    MediumCVSS 6.5Proof of conceptEPSS 1%

    spiceworks · spiceworksSep 17, 2014

  • CVE-2015-6021
    24Monitor

    Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.

    MediumCVSS 6.1No exploitEPSS 1%

    spiceworks · desktopApr 9, 2017

  • Spiceworks Version <= 7.5.00107 is affected by XSS.

    MediumCVSS 5.4No exploitEPSS 1%

    spiceworks · spiceworksSep 1, 2020

  • CVE-2012-6658
    18Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML vi

    MediumCVSS 4.3Proof of conceptEPSS 2%

    spiceworks · spiceworksSep 17, 2014

  • CVE-2014-3740
    15Monitor

    Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or

    LowCVSS 3.5Proof of conceptEPSS 3%

    spiceworks · spiceworksSep 11, 2014