SysAid Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for SysAid products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

3

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

SysAid KEVs Added by Year

Loading...

4 SysAid KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-2777

SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection

High Not in CISA 24 Jun 2025
CVE-2025-2776

SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection

Confirmed In CISA 01 Jun 2026
CVE-2025-2775

SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

Confirmed In CISA 01 Jun 2026
CVE-2023-47246

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot,...

Confirmed In CISA 13 Nov 2023

Common Vulnerability Classes (CWE)

  • CWE-611 — Improper Restriction of XML External Entity Reference 3
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology