glpi-project kayıtları
glpi-project üreticisine ait 206 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,5
- Silahlaştırılmış
- 3 · %1,5
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %44,7
- Yayından KEV’e ortanca
- 169 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')51
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')44
- CWE-284 Improper Access Control13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor13
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
206 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2022-35914Silahlaştırılmış | /vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.glpi-project · glpi · CWE-74 | Kritik9,8 | KEV | %99,9 | 19 Eyl 2022 |
65Bu hafta | CVE-2025-24799Silahlaştırılmış | GLPI allows unauthenticated SQL injection through the inventory endpointglpi-project · glpi · CWE-89 | Kritik9,8 | — | %86,7 | 18 Mar 2025 |
59Planlayın | CVE-2023-46727İstismar yok | GLPI SQL injection through inventory agent requestglpi-project · glpi · CWE-89 | Kritik9,8 | — | %67,7 | 13 Ara 2023 |
57Planlayın | CVE-2020-15175Kavram kanıtı | Unauthenticated File Deletion in GLPIglpi-project · glpi · CWE-552 | Kritik9,1 | — | %71,6 | 7 Eki 2020 |
54Planlayın | CVE-2022-31061Kavram kanıtı | SQL injection on login page in GLPIglpi-project · glpi · CWE-89 | Kritik9,8 | — | %51,4 | 28 Haz 2022 |
54Planlayın | CVE-2023-35924İstismar yok | GLPI vulnerable to SQL injection via inventory agent requestglpi-project · glpi · CWE-89 | Kritik9,8 | — | %50,7 | 5 Tem 2023 |
53Planlayın | CVE-2023-36808Kavram kanıtı | GLPI vulnerable to SQL injection through Computer Virtual Machine informationglpi-project · glpi · CWE-89 | Kritik9,8 | — | %47,8 | 5 Tem 2023 |
51Planlayın | CVE-2024-29889Kavram kanıtı | GLPI contains an SQL injection through the saved searchesglpi-project · glpi · CWE-89 | Yüksek8,1 | — | %63,0 | 7 May 2024 |
50Planlayın | CVE-2023-41320İstismar yok | Account takeover via SQL Injection in UI layout preferences in GLPIglpi-project · glpi · CWE-89 | Kritik9,8 | — | %35,3 | 27 Eyl 2023 |
49Planlayın | CVE-2024-27098İstismar yok | Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPIglpi-project · glpi · CWE-918 | Kritik9,6 | — | %35,7 | 18 Mar 2024 |
49Planlayın | CVE-2022-39323İstismar yok | SQL Injection on REST API in GLPIglpi-project · glpi · CWE-89 | Kritik9,8 | — | %34,5 | 3 Kas 2022 |
46Planlayın | CVE-2021-43778Kavram kanıtı | Path traversal in GLPI barcode pluginglpi-project · barcode · CWE-22 | Yüksek7,5 | — | %52,7 | 24 Kas 2021 |
46Planlayın | CVE-2024-40638İstismar yok | GLPI allows account takeover via SQL Injection in AJAX scriptsglpi-project · glpi · CWE-89 | Yüksek8,8 | — | %38,3 | 15 Kas 2024 |
46Planlayın | CVE-2023-41326İstismar yok | Account takeover via Kanban feature in GLPIglpi-project · glpi · CWE-269 | Yüksek8,8 | — | %35,6 | 27 Eyl 2023 |
44Planlayın | CVE-2024-31456İstismar yok | GLPI contains an authenticated SQL injectionglpi-project · glpi · CWE-89 | Orta6,5 | — | %59,1 | 7 May 2024 |
44Planlayın | CVE-2024-27096İstismar yok | SQL Injection in through the search engineglpi-project · glpi · CWE-89 | Orta6,5 | — | %58,8 | 18 Mar 2024 |
44Planlayın | CVE-2023-43813İstismar yok | glpi Authenticated SQL Injectionglpi-project · glpi · CWE-89 | Yüksek8,8 | — | %30,9 | 13 Ara 2023 |
43Planlayın | CVE-2024-50339İstismar yok | GLPI vulnerable to unauthenticated session hijackingglpi-project · glpi · CWE-79 | Kritik9,3 | — | %18,7 | 11 Ara 2024 |
42Planlayın | CVE-2022-31056Kavram kanıtı | SQL injection with _actor parameter in GLPIglpi-project · glpi · CWE-89 | Kritik9,8 | — | %9,0 | 28 Haz 2022 |
41Planlayın | CVE-2024-37149İstismar yok | GLPI allows remote code execution through the plugin loaderglpi-project · glpi · CWE-73 | Yüksek8,8 | — | %21,1 | 10 Tem 2024 |
41Planlayın | CVE-2025-24801Kavram kanıtı | GLPI allows authenticated remote code executionglpi-project · glpi · CWE-434 | Yüksek8,8 | — | %21,0 | 18 Mar 2025 |
41Planlayın | CVE-2022-34128Kavram kanıtı | The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.glpi-project · positions · CWE-434 | Kritik9,8 | — | %7,8 | 15 Nis 2023 |
40Planlayın | CVE-2021-44617İstismar yok | A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.glpi-project · glpi · CWE-89 | Kritik9,8 | — | %2,1 | 27 Mar 2022 |
40Planlayın | CVE-2024-31705İstismar yok | An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of usCWE-78 | Kritik9,8 | — | %1,9 | 29 Nis 2024 |
39İzleyin | CVE-2017-11184İstismar yok | SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.glpi-project · glpi · CWE-89 | Kritik9,8 | — | %1,6 | 28 Tem 2017 |
- CVE-2022-3591499Hemen
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100glpi-project · glpi19 Eyl 2022
- CVE-2025-2479965Bu hafta
GLPI allows unauthenticated SQL injection through the inventory endpoint
KritikCVSS 9,8SilahlaştırılmışEPSS %87glpi-project · glpi18 Mar 2025
- CVE-2023-4672759Planlayın
GLPI SQL injection through inventory agent request
KritikCVSS 9,8İstismar yokEPSS %68glpi-project · glpi13 Ara 2023
- CVE-2020-1517557Planlayın
Unauthenticated File Deletion in GLPI
KritikCVSS 9,1Kavram kanıtıEPSS %72glpi-project · glpi7 Eki 2020
- CVE-2022-3106154Planlayın
SQL injection on login page in GLPI
KritikCVSS 9,8Kavram kanıtıEPSS %51glpi-project · glpi28 Haz 2022
- CVE-2023-3592454Planlayın
GLPI vulnerable to SQL injection via inventory agent request
KritikCVSS 9,8İstismar yokEPSS %51glpi-project · glpi5 Tem 2023
- CVE-2023-3680853Planlayın
GLPI vulnerable to SQL injection through Computer Virtual Machine information
KritikCVSS 9,8Kavram kanıtıEPSS %48glpi-project · glpi5 Tem 2023
- CVE-2024-2988951Planlayın
GLPI contains an SQL injection through the saved searches
YüksekCVSS 8,1Kavram kanıtıEPSS %63glpi-project · glpi7 May 2024
- CVE-2023-4132050Planlayın
Account takeover via SQL Injection in UI layout preferences in GLPI
KritikCVSS 9,8İstismar yokEPSS %35glpi-project · glpi27 Eyl 2023
- CVE-2024-2709849Planlayın
Blind Server-Side Request Forgery (SSRF) using Arbitrary Object Instantiation in GLPI
KritikCVSS 9,6İstismar yokEPSS %36glpi-project · glpi18 Mar 2024
- CVE-2022-3932349Planlayın
SQL Injection on REST API in GLPI
KritikCVSS 9,8İstismar yokEPSS %34glpi-project · glpi3 Kas 2022
- CVE-2021-4377846Planlayın
Path traversal in GLPI barcode plugin
YüksekCVSS 7,5Kavram kanıtıEPSS %53glpi-project · barcode24 Kas 2021
- CVE-2024-4063846Planlayın
GLPI allows account takeover via SQL Injection in AJAX scripts
YüksekCVSS 8,8İstismar yokEPSS %38glpi-project · glpi15 Kas 2024
- CVE-2023-4132646Planlayın
Account takeover via Kanban feature in GLPI
YüksekCVSS 8,8İstismar yokEPSS %36glpi-project · glpi27 Eyl 2023
- CVE-2024-3145644Planlayın
GLPI contains an authenticated SQL injection
OrtaCVSS 6,5İstismar yokEPSS %59glpi-project · glpi7 May 2024
- CVE-2024-2709644Planlayın
SQL Injection in through the search engine
OrtaCVSS 6,5İstismar yokEPSS %59glpi-project · glpi18 Mar 2024
- CVE-2023-4381344Planlayın
glpi Authenticated SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %31glpi-project · glpi13 Ara 2023
- CVE-2024-5033943Planlayın
GLPI vulnerable to unauthenticated session hijacking
KritikCVSS 9,3İstismar yokEPSS %19glpi-project · glpi11 Ara 2024
- CVE-2022-3105642Planlayın
SQL injection with _actor parameter in GLPI
KritikCVSS 9,8Kavram kanıtıEPSS %9glpi-project · glpi28 Haz 2022
- CVE-2024-3714941Planlayın
GLPI allows remote code execution through the plugin loader
YüksekCVSS 8,8İstismar yokEPSS %21glpi-project · glpi10 Tem 2024
- CVE-2025-2480141Planlayın
GLPI allows authenticated remote code execution
YüksekCVSS 8,8Kavram kanıtıEPSS %21glpi-project · glpi18 Mar 2025
- CVE-2022-3412841Planlayın
The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.
KritikCVSS 9,8Kavram kanıtıEPSS %8glpi-project · positions15 Nis 2023
- CVE-2021-4461740Planlayın
A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.
KritikCVSS 9,8İstismar yokEPSS %2glpi-project · glpi27 Mar 2022
- CVE-2024-3170540Planlayın
An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of us
KritikCVSS 9,8İstismar yokEPSS %229 Nis 2024
- CVE-2017-1118439İzleyin
SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.
KritikCVSS 9,8İstismar yokEPSS %2glpi-project · glpi28 Tem 2017