4.8

CVSS3.1

CVE-2024-51496 - LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.…

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution of malic…

📅 Published: Nov. 15, 2024, 3:45 p.m. 🔄 Last Modified: Nov. 21, 2024, 11:33 p.m.

4.8

CVSS3.1

CVE-2024-51495 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.…

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when editing a device. This vulnerability results …

📅 Published: Nov. 15, 2024, 3:44 p.m. 🔄 Last Modified: Nov. 20, 2024, 2:41 p.m.

4.8

CVSS3.1

CVE-2024-51494 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPorts…

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port settings. This vulnerability…

📅 Published: Nov. 15, 2024, 3:43 p.m. 🔄 Last Modified: Nov. 20, 2024, 2:40 p.m.

4.8

CVSS3.1

CVE-2024-50355 - LibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple Endpoints

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the device Display Name, if java script code is inside the name of the device Display Name, its can be …

📅 Published: Nov. 15, 2024, 3:41 p.m. 🔄 Last Modified: Nov. 20, 2024, 2:39 p.m.

7.5

CVSS3.1

CVE-2024-41784 - IBM Sterling Secure Proxy directory traversal

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.

📅 Published: Nov. 15, 2024, 3:40 p.m. 🔄 Last Modified: Nov. 20, 2024, 2:35 p.m.

4.8

CVSS3.1

CVE-2024-50352 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/…

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding a service to a devic…

📅 Published: Nov. 15, 2024, 3:40 p.m. 🔄 Last Modified: Nov. 20, 2024, 2:37 p.m.

6.1

CVSS3.1

CVE-2022-20657 - Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Cross-Site Scripting Vuln…

A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. This vulnerability exists because the web-based management interface does not p…

📅 Published: Nov. 15, 2024, 3:39 p.m. 🔄 Last Modified: July 31, 2025, 3:05 p.m.

6.1

CVSS3.1

CVE-2022-20663 - Secure Network Analytics Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insufficient v…

📅 Published: Nov. 15, 2024, 3:38 p.m. 🔄 Last Modified: July 31, 2025, 3:49 p.m.

7.5

CVSS3.1

CVE-2022-20685 - Multiple Cisco Products Snort Modbus Denial of Service Vulnerability

A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modbus traffic. An attacker could exploit t…

📅 Published: Nov. 15, 2024, 3:36 p.m. 🔄 Last Modified: June 24, 2025, 2:47 p.m.

6.5

CVSS3.1

CVE-2022-20656 - Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Path Traversal Vulnerabil…

A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker must have valid credentials on the system. This vulnerabi…

📅 Published: Nov. 15, 2024, 3:36 p.m. 🔄 Last Modified: July 31, 2025, 3:05 p.m.
Total resulsts: 343947
Page 7334 of 34,395
« previous page » next page
Filters