CVE security advisories and vulnerability history for Now Platform by ServiceNow.
11
Total CVEs
Published
2
In CISA KEV
Exploited in the wild
3
Public exploits
PoC or exploit code
7.8
Avg CVSS
2023–2025
Last updated
Overview
ServiceNow Now Platform has 11 published CVE records since 2023, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 3 have a known public exploit. The average CVSS base score across scored CVEs is 7.8.
This page aggregates every publicly disclosed vulnerability (CVE) affecting ServiceNow Now Platform, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of ServiceNow Now Platform's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical4
High3
Medium4
Low0
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of ServiceNow Now Platform's CVEs are confirmed exploited in the wild.
Public exploits
3
3 of ServiceNow Now Platform's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every ServiceNow Now Platform version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about ServiceNow Now Platform vulnerabilities.
How many CVEs does ServiceNow Now Platform have?
ServiceNow Now Platform has 11 published CVE records since 2023.
How many ServiceNow Now Platform CVEs are in CISA KEV?
Yes — 2 of ServiceNow Now Platform's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for ServiceNow Now Platform vulnerabilities?
Yes — 3 of ServiceNow Now Platform's CVEs have a known public exploit.
Which versions of ServiceNow Now Platform are affected?
97 distinct ServiceNow Now Platform versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in ServiceNow Now Platform CVEs?
ServiceNow Now Platform's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-184 (Incomplete List of Disallowed Inputs), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-639 (Authorization Bypass Through User-Controlled Key).
How many critical ServiceNow Now Platform vulnerabilities are there?
ServiceNow Now Platform has 4 critical and 3 high-severity CVEs.
What is the average severity of ServiceNow Now Platform CVEs?
The average CVSS base score across ServiceNow Now Platform's scored CVEs is 7.8.