snipe
CVE Severity Distribution (All Time)
Timeline Overview
Recent CVEs
View allUsers with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships vi…
Cross-Site Request Forgery (CSRF) in GitHub repository snipe/snipe-it prior to v.6.2.3.
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.2.2.
Improper Authentication in GitHub repository snipe/snipe-it prior to 6.0.10.
Cross-site Scripting (XSS) - Stored in GitHub repository snipe/snipe-it prior to v6.0.11.
Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password …
Missing Authorization in GitHub repository snipe/snipe-it prior to 5.4.4.
Stored Cross Site Scripting vulnerability in the checked_out_to parameter in GitHub repository snipe/snipe-it prior to 5.4.3. The vulnerability is ca…
Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of…