Vulnerabilidades em Glpi-Project
182 resultadosAnálise Vexday
GLPI-Project apresenta um perfil de risco baixo com apenas 1 vulnerabilidade catalogada e nenhuma sob exploração ativa confirmada. A fraqueza identificada (CWE-203 - Observação de Diferenças de Informações) não é classificada como crítica e não gerou novos registros nos últimos 90 dias, indicando que o risco é estável e historicamente contido.
CVE-2024-50339CRITICALGLPI vulnerable to unauthenticated session hijackingEPSS 18.7%CVE-2020-11060HIGHRemote Code Execution in GLPIEPSS 10.9%CVE-2022-31056CRITICALSQL injection with _actor parameter in GLPIEPSS 9.0%CVE-2020-11034MEDIUMbypass of manageRedirect in GLPIEPSS 7.6%CVE-2025-32786HIGHGLPI Inventory Plugin is Vulnerable to Unauthenticated SQL InjectionEPSS 7.0%CVE-2022-31062MEDIUMUnauthenticated Local File InclusionEPSS 5.9%CVE-2021-39211MEDIUMDisclosure of GLPI and server information in telemetry endpointEPSS 4.7%CVE-2021-21327MEDIUMUnsafe Reflection in getItemForItemtype()EPSS 2.3%CVE-2020-5248HIGHPublic GLPIKEY can be used to decrypt any data in GLPIEPSS 1.5%CVE-2021-21324MEDIUMInsecure Direct Object Reference (IDOR) on "Solutions"EPSS 1.4%CVE-2021-21326HIGHHorizontal Privilege EscalationEPSS 1.4%CVE-2022-24867HIGHLDAP password exposure in glpiEPSS 1.3%CVE-2023-46726HIGHGLPI Remote code execution from LDAP server configuration form on PHP 7.4EPSS 1.3%CVE-2023-42462HIGHFile deletion through document upload process in GLPIEPSS 1.3%CVE-2020-15108HIGHSQL Injection in glpiEPSS 1.2%CVE-2024-43416HIGHGLPI vulnerable to enumeration of users' email addresses by unauthenticated userEPSS 1.2%CVE-2022-35947CRITICALSQL injection in GLPIEPSS 1.2%CVE-2020-26212HIGHAny GLPI CalDAV calendars is read-only for every authenticated userEPSS 1.2%CVE-2023-42461MEDIUMSQL injection in ITIL actors in GLPIEPSS 1.2%CVE-2020-15176HIGHSQL injection in GLPIEPSS 1.1%