Vulnerabilities
148 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-12420 | Unauthenticated User Impersonation in ServiceNow AI Platform CVE-2025-12420 is a critical permission-preservation flaw (CWE-250) in the ServiceNow AI Platform that lets an unauthenticated, network-attainable attacker impersonate another user with no privileges, user interaction, or special conditions required. Once impersonating a victim, the attacker can perform every operation that user is entitled to perform, with high impact on confidentiality, integrity, and availability across the affected scope. The issue affects instances using the Now Assist AI Agents and Virtual Agent API components, in both ServiceNow-hosted and self-hosted/partner deployments. ServiceNow deployed the fix to hosted instances in October 2025 and shipped security updates to self-hosted, partner, and uniquely configured hosted customers, and addressed the flaw in listed Store App versions. There is no public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 49.1% (99th percentile) indicates a high near-term probability of exploitation, so unpatched self-hosted instances remain the main residual risk. Do: Self-hosted, partner, and uniquely configured hosted customers should promptly apply the ServiceNow security update or upgrade, and customers using the affected Store Apps should upgrade Now Assist AI Agents and Virtual Agent API to the fixed listed versions in ServiceNow's advisory; hosted-instance customers should verify ServiceNow applied the October 2025 fix. Review logs for anomalous impersonation activity (unexpected impersonation or swap-by events) to detect possible abuse, since exploitation requires no authentication or user interaction. | 9.3 | 49% |
| massmillions of end users across thousands of enterprise customer instances (hosted fleet largely patched in Oct 2025; residual exposure concentrated in unpatched… | ||
| CVE-2025-6445 +1 in the same advisory: …6444 | ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. ServiceStack FindType Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ServiceStack. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of the FindType method. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25837. NVD description · AI analysis pending | 8.1 group max | 1% |
| — | ||
| CVE-2024-11267 +1 in the same advisory: …12301 | The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor t The JSP Store Locator WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing user with Contributor to perform SQL injection attacks. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2025-1315 | The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. The InWave Jobs plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 3.5.1. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-13255 | Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Serv Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-11018 | Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which co Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-8923 +1 in the same advisory: …8924 | ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes. NVD description · AI analysis pending | 9.3 group max | 1% |
| — | ||
| CVE-2024-9848 | The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-6202 | HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. HaloITSM versions up to 2.146.1 are affected by a SAML XML Signature Wrapping (XSW) vulnerability. When having a SAML integration configured, anonymous actors could impersonate arbitrary HaloITSM users by just knowing their email address. HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-38432 | Matrix Tafnit v8 - CWE-646: Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-4879 +1 in the same advisory: …5217 | Unauthenticated RCE via Jelly Template Injection in ServiceNow Now Platform CVE-2024-4879 is an improper input validation flaw (CWE-1287) in the ServiceNow Now Platform that permits jelly template injection through UI macros. An unauthenticated attacker can submit crafted input that is improperly handled by the jelly templating engine, resulting in code execution on the instance. Successful exploitation therefore grants unauthenticated remote code execution on affected ServiceNow deployments. Organizations running Utah, Vancouver, or Washington DC Now Platform releases are affected, including the many enterprises and government agencies that expose ServiceNow portals to the internet for employee, customer, or citizen use. The flaw is confirmed exploited in the wild (added to CISA KEV on 2024-07-29), carries a maximal EPSS estimate of 100% probability of exploitation within 30 days, and has no known public PoC. Do: Apply the patched Now Platform builds for the Utah, Vancouver, and Washington DC release trains per ServiceNow's advisory, as required by the CISA KEV listing. Because exploitation is confirmed and requires no authentication, prioritize internet-facing instances, restrict public access where feasible until patched, and review instance logs for signs of exploitation. Confirm every release train in your environment is covered, since all three (Utah, Vancouver, Washington DC) are affected. | 9.3 group max | 100% | KEV |
| masslikely millions of enterprise users across tens of thousands of deployed Now Platform instances, many of them internet-exposed (order-of-magnitude estimate;… | |
| CVE-2024-25844 | An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate pri An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-25841 | In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting ( In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection. NVD description · AI analysis pending | 5.9 | <1% | PoC |
| — | |
| CVE-2023-51839 | DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm. DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm. NVD description · AI analysis pending | 9.1 | <1% |
| — | ||
| CVE-2023-40921 | SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2023-45382 | In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restric In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-45383 | In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-4309 | Election Services Co. Election Services Co. (ESC) Internet Election Service is vulnerable to SQL injection in multiple pages and parameters. These vulnerabilities allow an unauthenticated, remote attacker to read or modify data for any elections that share the same backend database. ESC deactivated older and unused elections and enabled web application firewall (WAF) protection for current and future elections on or around 2023-08-12. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2023-39987 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions. Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ajay Lulia wSecure Lite plugin <= 2.5 versions. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2023-3720 | The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-1298 | ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Lay ServiceNow has released upgrades and patches that address a Reflected Cross-Site scripting (XSS) vulnerability that was identified in the ServiceNow Polaris Layout. This vulnerability would enable an authenticated user to inject arbitrary scripts. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-43684 | ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * Rome prior to Patch 10 Hot Fix 1 * San Diego prior to Patch 7 * Tokyo prior to Tokyo Patch 1; and * Utah prior to Utah General Availability If this ACL bypass issue were to be successfully exploited, it potentially could allow an authenticated user to obtain sensitive information from tables missing authorization controls. NVD description · AI analysis pending | 6.5 | 2% |
| — | ||
| CVE-2023-30764 | OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. OS command injection vulnerability exists in KB-AHR series and KB-IRIP series. If this vulnerability is exploited, an arbitrary OS command may be executed on the product or the device settings may be altered. Affected products and versions are as follows: KB-AHR04D versions prior to 91110.1.101106.78, KB-AHR08D versions prior to 91210.1.101106.78, KB-AHR16D versions prior to 91310.1.101106.78, KB-IRIP04A versions prior to 95110.1.100290.78A, KB-IRIP08A versions prior to 95210.1.100290.78A, and KB-IRIP16A versions prior to 95310.1.100290.78A. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2023-3005 | A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. A vulnerability, which was classified as problematic, was found in SourceCodester Local Service Search Engine Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_area of the component POST Parameter Handler. The manipulation of the argument area with the input leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230349 was assigned to this vulnerability. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-1209 | Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts. Cross-Site Scripting (XSS) vulnerabilities exist in ServiceNow records allowing an authenticated attacker to inject arbitrary scripts. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2023-29552 | SLP DoS Amplification Flaw Affects VMware ESXi, SUSE Linux, NetApp CVE-2023-29552 is a protocol-level flaw in the IETF Service Location Protocol (SLP, RFC 2608) that permits an unauthenticated, remote attacker to register arbitrary services using spoofed UDP traffic sent to port 427. Any system running an SLP agent reachable on UDP 427 on an untrusted network can be abused as a reflector/amplifier, with reported amplification factors as high as roughly 2,200x, enabling large denial-of-service floods against third-party victims. The impact is availability only (CVSS 3.1: 7.5, A:H), and the attacker needs no privileges or user interaction. Affected parties include organizations running VMware ESXi, SUSE Linux Enterprise Server, or NetApp products (SMI-S Provider, Manager Server), as well as any host running the open-source Service Location Protocol implementation, since SLP is commonly enabled by default. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2023-11-08 and is under active exploitation, with a high EPSS of 65.9% (99th percentile). Do: Per the CISA required action, disable the SLP service (slpd) where it is not needed, or restrict UDP port 427 to trusted management networks and never expose it to the internet. Apply the mitigations or patches issued in the VMware, SUSE, and NetApp advisories, and inventory all hosts listening on 427/UDP, prioritizing internet-facing and untrusted-network systems since the flaw is under active exploitation. | 7.5 | 66% | KEV PoC ×2 |
| masshundreds of thousands of servers or more plausibly run SLP enabled by default (exact count, and the number exposing UDP 427 to the internet, unknown) | |
| CVE-2022-46389 | There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Pa There exists a reflected XSS within the logout functionality of ServiceNow versions lower than Quebec Patch 10 Hotfix 11b, Rome Patch 10 Hotfix 3b, San Diego Patch 9, Tokyo Patch 4, and Utah GA. This enables an unauthenticated remote attacker to execute arbitrary JavaScript code in the browser-based web console. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-2097 | A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. A vulnerability was found in SourceCodester Vehicle Service Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-226105 was assigned to this vulnerability. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — |