Spiceworks

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 9
    Known Exploited: 0
    2
    Critical Level Threats
    1
    High Level Threats
    5
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-43609

    An issue was discovered in Spiceworks Help Desk Server before 1.3.3. A Blind Boolean SQL injection vulnerability within the order_by_for_ticket function in app/models/reporting/database_query.rb allows an authenticated attacker to execute arbitrary SQL commands via the sort parameter. This can be leveraged to leak local files from the host system, leading to remote code execution (RCE) through deserialization of malicious data.

    Last Modified: Nov 21, 2024
    Published: Nov 08, 2023

    CVE-2020-25901

    Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.

    Last Modified: Nov 21, 2024
    Published: Dec 18, 2020

    CVE-2020-23451

    Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.

    Last Modified: Nov 21, 2024
    Published: Sep 15, 2020

    CVE-2020-23450

    Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.

    Last Modified: Nov 21, 2024
    Published: Sep 01, 2020

    CVE-2015-6021

    Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.

    Last Modified: Apr 20, 2025
    Published: Apr 10, 2017
    Items Per Page
    Spiceworks Vulnerabilities & Security CVEs | CVE-DB