VYPR
Vendor

Servicenow

Products
13
CVEs
37
Across products
58
Status
Private

Products

13

Recent CVEs

37
View all 37 CVEs →
  • CVE-2024-4879CriKEVJul 10, 2024
    risk 0.87cvss 9.8epss 1.00

    ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an…

  • CVE-2024-5217CriKEVJul 10, 2024
    risk 0.84cvss 9.8epss 1.00

    ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The…

  • CVE-2025-12420CriJan 12, 2026
    risk 0.67cvss 9.8epss 0.53

    A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a…

  • CVE-2026-74820CriAug 27, 2026
    risk 0.65cvss —epss 0.00

    ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and…

  • CVE-2026-6876CriAug 27, 2026
    risk 0.65cvss —epss 0.01

    ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow…

  • CVE-2026-18886CriAug 27, 2026
    risk 0.65cvss —epss 0.05

    ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in…

  • CVE-2026-18885CriAug 27, 2026
    risk 0.65cvss —epss 0.07

    ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify,…

  • CVE-2024-8923CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and…

  • CVE-2022-43684CriJun 13, 2023
    risk 0.64cvss 9.9epss 0.02

    ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present in the following supported ServiceNow releases: * Quebec prior to Patch 10 Hot Fix 8b * …

  • CVE-2026-86860CriSep 24, 2026
    risk 0.60cvss —epss 0.00

    ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege…

  • CVE-2026-13016CriSep 24, 2026
    risk 0.60cvss —epss 0.00

    ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain…

  • CVE-2026-0542CriFeb 25, 2026
    risk 0.60cvss —epss 0.01

    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox.    ServiceNow addressed…

  • CVE-2026-86859HigSep 24, 2026
    risk 0.57cvss —epss 0.00

    ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be…

  • CVE-2026-86858HigSep 24, 2026
    risk 0.57cvss —epss 0.00

    ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In…

  • CVE-2018-7748HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.03

    report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media parameter.

  • CVE-2026-86857HigSep 24, 2026
    risk 0.55cvss —epss 0.00

    ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be…

  • CVE-2025-3648HigJul 8, 2025
    risk 0.53cvss —epss 0.02

    A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configurations, this vulnerability could enable unauthenticated and authenticated users to use range query…

  • CVE-2019-0032HigApr 10, 2019
    risk 0.51cvss 7.8epss 0.00

    A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization. Affected…

  • CVE-2024-8924HigOct 29, 2024
    risk 0.49cvss 7.5epss 0.01

    ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized information. ServiceNow deployed an update to hosted instances, and ServiceNow provided the…

  • CVE-2025-0337MedMar 6, 2025
    risk 0.42cvss 6.5epss 0.00

    ServiceNow has addressed an authorization bypass vulnerability that was identified in the Washington release of the Now Platform. This vulnerability, if exploited, potentially could enable an authenticated user to access unauthorized data stored within the Now Platform that the…