ServiceNow
First CVE: Apr 10, 2023Active for: 3 years
22
CVEs Published
More CVEs Published than 42% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
7.1
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked CNAs
9.1%
In CISA KEV
Higher KEV Rate than 98% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by ServiceNow as a CNA, 50.0% affect products that ServiceNow develops as a vendor.
50.0%
50.0%
Self-reported: 11Third-party: 11
Of all the CVEs published that affect products developed by ServiceNow, 61.1% are self-published by ServiceNow as a CNA.
61.1%
38.9%
Self-published: 11Published by other CNAs: 7
Trends Over Time
The number and severity of CVEs published by ServiceNow over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2023
3 years ago
Most Recent CVE
Jul 13, 2026
11 days ago
Top CVEs
All CVEs published by ServiceNow as a CNA, regardless of affected vendor or product.
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5217CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a | Jul 10, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-4879CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthentica | Jul 10, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-12420CRITICAL A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the imperson | Jan 12, 2026 | 9.8 | 61 | NO | NO |
CVE-2026-6875CRITICAL ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certai | Jul 13, 2026 | 9.5 | 50 | NO | NO |
CVE-2024-5178MEDIUM ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow an | Jul 10, 2024 | 4.9 | 36 | NO | NO |
CVE-2026-0542CRITICAL ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certa | Feb 25, 2026 | 9.2 | 32 | NO | NO |
CVE-2024-8923CRITICAL ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code | Oct 29, 2024 | 10.0 | 31 | NO | NO |
CVE-2022-39048MEDIUM A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a | Apr 10, 2023 | 6.1 | 31 | NO | YES |
CVE-2025-3648HIGH A vulnerability has been identified in the Now Platform that could result in data being inferred without authorization. Under certain conditional access control list (ACL) configur | Jul 8, 2025 | 8.2 | 28 | NO | NO |
CVE-2024-8924HIGH ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorize | Oct 29, 2024 | 7.5 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA22 CVEs
59%
14%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None13 (59.1%)
Unknown0 (0.0%)
Required7 (31.8%)
Privileges Required
Low4 (18.2%)
High1 (4.5%)
None17 (77.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (22 CVEs).
CISA KEV
2 CVEs
9.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
13.6% of CVEs· 98th percentile
ExploitDB
1 CVE
4.5% of CVEs· 94th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by ServiceNow as a CNA.
Media Mentions
Media articles that mention a CVE ID published by ServiceNow as a CNA — matched by CVE ID, not by organization name.