CVEs we hold for Servicenow
Records whose assigning authority named Servicenow as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-74820Unauthenticated SQL Injection via Dynamic Schema ORDER BY ClauseServiceNow AI Platform CVE-2026-6876Sandbox Escape in ServiceNow AI PlatformServiceNow AI Platform CVE-2026-6875Sandbox Escape in ServiceNow AI PlatformServiceNow AI Platform CVE-2026-18886Unauthenticated Privilege Escalation via System Configuration Image Upload ProcessorServiceNow AI Platform CVE-2026-18885Unauthenticated Remote Code Execution in GraphQL Composite Data APIServiceNow AI Platform CVE-2026-0542Remote Code Execution in ServiceNow AI PlatformServiceNow AI Platform CVE-2025-3648Data Inference in Now Platform via Conditional ACLsServiceNow Now Platform CVE-2025-3089Broken Access Control in ServiceNow AI PlatformServiceNow AI Platform CVE-2025-12420Unauthenticated Privilege Escalation in ServiceNow AI PlatformServiceNow Virtual Agent API CVE-2025-11450Reflected Cross Site Scripting in ServiceNow AI PlatformServiceNow AI Platform CVE-2025-11449Reflected Cross Site Scripting in ServiceNow AI PlatformServiceNow AI Platform CVE-2025-0337Authorization bypass in Now PlatformServiceNow Now Platform CVE-2024-8924Unauthenticated Blind SQL Injection in Core PlatformServiceNow Now Platform CVE-2024-8923Sandbox Escape in Now PlatformServiceNow Now Platform CVE-2024-5890HTML Injection in the Assessment pluginServiceNow Now Platform CVE-2024-5217Incomplete Input Validation in GlideExpression ScriptServiceNow Now Platform CVE-2024-5178Incomplete Input Validation in SecurelyAccess APIServiceNow Now Platform CVE-2024-4879Jelly Template Injection Vulnerability in ServiceNow UI MacrosServiceNow Now Platform CVE-2023-3442Missing Authorization in Jenkins plug-in for ServiceNow DevOpsServiceNow DevOps CVE-2023-3414Cross-Site Request Forgery (CSRF) in Jenkins Plug-in for ServiceNow DevOpsServiceNow DevOps CVE-2022-46389Cross-Site Scripting (XSS) vulnerability found on logout functionalityServiceNow Now Platform CVE-2022-43684ACL bypass in Reporting functionalityServiceNow Now Platform CVE-2022-39048Cross-Site Scripting (XSS) vulnerability in ServiceNow UI page assessment_redirectServicenow Now Platform 26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.