ServiceNow

First CVE: Apr 10, 2023Active for: 3 years
22
CVEs Published
More CVEs Published than 42% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked CNAs
9.1%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by ServiceNow as a CNA, 50.0% affect products that ServiceNow develops as a vendor.

50.0%
50.0%
Self-reported: 11Third-party: 11

Of all the CVEs published that affect products developed by ServiceNow, 61.1% are self-published by ServiceNow as a CNA.

61.1%
38.9%
Self-published: 11Published by other CNAs: 7

Trends Over Time

The number and severity of CVEs published by ServiceNow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2023
3 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Top CVEs

All CVEs published by ServiceNow as a CNA, regardless of affected vendor or product.

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a
Jul 10, 20249.898YESYES
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthentica
Jul 10, 20249.898YESYES
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the imperson
Jan 12, 20269.861NONO
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certai
Jul 13, 20269.550NONO
ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an
Jul 10, 20244.936NONO
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certa
Feb 25, 20269.232NONO
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code
Oct 29, 202410.031NONO
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a
Apr 10, 20236.131NOYES
A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configur
Jul 8, 20258.228NONO
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorize
Oct 29, 20247.524NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA22 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None13 (59.1%)
Unknown0 (0.0%)
Required7 (31.8%)
Privileges Required
Low4 (18.2%)
High1 (4.5%)
None17 (77.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (22 CVEs).

CISA KEV
2 CVEs
9.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
13.6% of CVEs· 98th percentile
ExploitDB
1 CVE
4.5% of CVEs· 94th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by ServiceNow as a CNA.

Media Mentions

Media articles that mention a CVE ID published by ServiceNow as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs