vciy

CVEs we hold for Servicenow

Records whose assigning authority named Servicenow as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-74820Unauthenticated SQL Injection via Dynamic Schema ORDER BY ClauseServiceNow AI Platform
CVE-2026-6876Sandbox Escape in ServiceNow AI PlatformServiceNow AI Platform
CVE-2026-6875Sandbox Escape in ServiceNow AI PlatformServiceNow AI Platform
CVE-2026-18886Unauthenticated Privilege Escalation via System Configuration Image Upload ProcessorServiceNow AI Platform
CVE-2026-18885Unauthenticated Remote Code Execution in GraphQL Composite Data APIServiceNow AI Platform
CVE-2026-0542Remote Code Execution in ServiceNow AI PlatformServiceNow AI Platform
CVE-2025-3648Data Inference in Now Platform via Conditional ACLsServiceNow Now Platform
CVE-2025-3089Broken Access Control in ServiceNow AI PlatformServiceNow AI Platform
CVE-2025-12420Unauthenticated Privilege Escalation in ServiceNow AI PlatformServiceNow Virtual Agent API
CVE-2025-11450Reflected Cross Site Scripting in ServiceNow AI PlatformServiceNow AI Platform
CVE-2025-11449Reflected Cross Site Scripting in ServiceNow AI PlatformServiceNow AI Platform
CVE-2025-0337Authorization bypass in Now PlatformServiceNow Now Platform
CVE-2024-8924Unauthenticated Blind SQL Injection in Core PlatformServiceNow Now Platform
CVE-2024-8923Sandbox Escape in Now PlatformServiceNow Now Platform
CVE-2024-5890HTML Injection in the Assessment pluginServiceNow Now Platform
CVE-2024-5217Incomplete Input Validation in GlideExpression ScriptServiceNow Now Platform
CVE-2024-5178Incomplete Input Validation in SecurelyAccess APIServiceNow Now Platform
CVE-2024-4879Jelly Template Injection Vulnerability in ServiceNow UI MacrosServiceNow Now Platform
CVE-2023-3442Missing Authorization in Jenkins plug-in for ServiceNow DevOpsServiceNow DevOps
CVE-2023-3414Cross-Site Request Forgery (CSRF) in Jenkins Plug-in for ServiceNow DevOpsServiceNow DevOps
CVE-2023-1298no title heldServiceNow Now User Experience
CVE-2023-1209no title heldServiceNow Records
CVE-2022-46886no title heldServiceNow
CVE-2022-46389Cross-Site Scripting (XSS) vulnerability found on logout functionalityServiceNow Now Platform
CVE-2022-43684ACL bypass in Reporting functionalityServiceNow Now Platform
CVE-2022-39048Cross-Site Scripting (XSS) vulnerability in ServiceNow UI page assessment_redirectServicenow Now Platform

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.