Vulnerabilidades en Servicenow
31 resultadosAnálisis Vexday
ServiceNow apresenta um perfil de risco mínimo na base Vexday com apenas 1 CVE registrado, sem ocorrências de ataque ativo (KEV) ou vulnerabilidades críticas. A fraqueza identificada é CWE-79 (cross-site scripting), de baixa severidade, sem atividade de exploração recente ou publicações nos últimos 90 dias.
CVE-2023-1209MEDIUMCross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts.EPSS 0.4%CVE-2025-11449MEDIUMReflected Cross Site Scripting in ServiceNow AI PlatformEPSS 0.4%CVE-2025-11450MEDIUMReflected Cross Site Scripting in ServiceNow AI PlatformEPSS 0.4%CVE-2025-3089MEDIUMBroken Access Control in ServiceNow AI PlatformEPSS 0.4%CVE-2024-5890MEDIUMHTML Injection in the Assessment pluginEPSS 0.3%CVE-2022-46886MEDIUMThere exists an open redirect within the response list update functionality of ServiceNow. This allows attackers to redirect users to arbitrEPSS 0.3%CVE-2026-86860CRITICALUnauthenticated Sensitive Data Disclosure in ServiceNow AI PlatformEPSS 0.3%CVE-2026-86859HIGHUnauthenticated Arbitrary Record Disclosure in ServiceNow AI PlatformEPSS 0.3%CVE-2026-13016CRITICALUnauthenticated SQL Injection in ServiceNow AI PlatformEPSS 0.3%CVE-2026-86858HIGHUnauthenticated Privilege Escalation via GraphQL in ServiceNow AI PlatformEPSS 0.3%CVE-2026-86857HIGHAuthorization Bypass in ServiceNow AI PlatformEPSS 0.3%