Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
snipe-it Vendor: snipeitapp

About This Product

snipe-it is a software product offered by snipeitapp. This product is widely deployed in production environments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The moderate vulnerability count reflects ongoing security research and responsible disclosure practices. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 50 known vulnerabilities affecting snipeitapp snipe-it. This includes 2 critical-severity issues and 13 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2019 to 2026, indicating a sustained research interest and ongoing security attention. 35 medium-severity issues complete the vulnerability landscape. Organizations should prioritize patching based on deployment context, asset criticality, and exploitation likelihood rather than severity alone.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2019-10118 2019-03-27 2024-11-21 6.1 4.3 Likely
CVE-2021-3858 2021-10-19 2024-11-21 8.8 6.8 Likely
CVE-2021-3863 2021-10-19 2024-11-21 6.1 4.3 Likely
CVE-2021-3879 2021-10-19 2024-11-21 5.4 3.5 Unknown
CVE-2021-3931 2021-11-13 2024-11-21 4.3 4.3 Likely
CVE-2021-3938 2021-11-13 2024-11-21 5.4 3.5 Unknown
CVE-2021-3961 2021-11-19 2024-11-21 5.4 3.5 Unknown
CVE-2021-4018 2021-12-01 2024-11-21 5.4 3.5 Unknown
CVE-2021-4075 2021-12-06 2024-11-21 7.2 6.5 Likely
CVE-2021-4089 2021-12-10 2024-11-21 4.3 4.0 Likely
CVE-2021-4108 2021-12-14 2024-11-21 6.1 4.3 Likely
CVE-2021-4130 2021-12-18 2024-11-21 8.8 6.8 Likely
CVE-2022-0179 2022-01-12 2024-11-21 5.4 4.9 Unknown
CVE-2022-0178 2022-01-13 2026-02-24 6.3 5.5 Likely
CVE-2022-0569 2022-02-14 2026-02-24 5.3 4.3 Likely
CVE-2022-0579 2022-02-14 2026-02-24 6.5 4.0 Likely
CVE-2022-0611 2022-02-16 2026-02-24 6.3 6.5 Likely
CVE-2022-0622 2022-02-17 2024-11-21 5.3 5.0 Likely
CVE-2022-1155 2022-03-30 2024-11-21 7.4 6.5 Likely
CVE-2022-1380 2022-04-16 2024-11-21 5.4 3.5 Unknown
CVE-2022-1445 2022-04-24 2024-11-21 5.4 3.5 Unknown
CVE-2022-1511 2022-04-28 2024-11-21 6.5 4.0 Likely
CVE-2022-23064 2022-05-02 2024-11-21 8.8 6.8 Likely
CVE-2022-32060 2022-07-07 2024-11-21 4.8 3.5 Unknown
CVE-2022-32061 2022-07-07 2024-11-21 4.8 3.5 Unknown
CVE-2022-2997 2022-08-25 2024-11-21 8.0 - -
CVE-2022-3035 2022-08-29 2024-11-21 4.8 - -
CVE-2022-3173 2022-09-17 2024-11-21 4.3 - -
CVE-2022-44380 2022-12-25 2025-04-15 5.4 - -
CVE-2022-44381 2022-12-25 2025-04-15 5.3 - -
CVE-2023-5452 2023-10-06 2024-11-21 5.4 - -
CVE-2023-5511 2023-10-11 2024-11-21 8.8 - -
CVE-2024-5685 2024-06-14 2025-03-07 7.6 - -
CVE-2024-48987 2024-10-11 2025-05-22 6.6 - -
CVE-2024-51093 2024-11-12 2024-11-21 8.7 - -
CVE-2024-51094 2024-11-12 2025-05-22 8.0 - -
CVE-2025-47226 2025-05-02 2025-06-03 5.0 - -
CVE-2025-59712 2025-09-19 2025-09-23 6.4 - -
CVE-2025-59713 2025-09-19 2025-09-23 6.8 - -
CVE-2025-63601 2025-11-05 2025-12-01 9.9 - -
CVE-2025-64027 2025-11-20 2025-11-26 6.1 - -
CVE-2025-65621 2025-12-01 2025-12-04 5.4 - -
CVE-2025-65622 2025-12-01 2025-12-03 5.4 - -
CVE-2025-15602 2026-03-06 2026-04-17 8.8 - -
CVE-2026-38533 2026-04-14 2026-05-01 6.5 - -
CVE-2026-37709 2026-05-07 2026-05-12 9.8 - -
CVE-2026-44831 2026-05-26 2026-05-26 4.8 - -
CVE-2026-44832 2026-05-26 2026-05-26 8.8 - -
CVE-2026-44833 2026-05-26 2026-05-26 5.9 - -
CVE-2026-48507 2026-06-08 2026-06-09 7.1 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for snipeitapp snipe-it by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.