6.5

CVSS3.1

CVE-2022-20652 - Cisco Tetration Command Injection Vulnerability

A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient โ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:58 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2022-20655 -

A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient validation of a process argument on an affected device. An attacker could exploit this vuโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:56 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS3.1

CVE-2024-52526 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/services.โ€ฆ

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when adding a service to a device. This vulnโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:55 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:39 p.m.

4.8

CVSS3.1

CVE-2024-51497 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/print-customoid.php

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users to inject arbitrary JavaScript through the "unit" parameter when creating a new OID. This vulnerability can leโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:46 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:41 p.m.

4.8

CVSS3.1

CVE-2024-51496 - LibreNMS has a Reflected XSS ('Cross-site Scripting') in librenms/includes/html/pages/wireless.inc.โ€ฆ

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows attackers to inject arbitrary JavaScript. This vulnerability results in the execution of malicโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:45 p.m. ๐Ÿ”„ Last Modified: Nov. 21, 2024, 11:33 p.m.

4.8

CVSS3.1

CVE-2024-51495 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/dev-overview-data.inc.โ€ฆ

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "overwrite_ip" parameter when editing a device. This vulnerability results โ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:44 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:41 p.m.

4.8

CVSS3.1

CVE-2024-51494 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsโ€ฆ

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary JavaScript through the "descr" parameter when editing a device's port settings. This vulnerabilityโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:43 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:40 p.m.

4.8

CVSS3.1

CVE-2024-50355 - LibreNMS has a Persistent XSS from Insecure Input Sanitization Affects Multiple Endpoints

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly sanitize the user input in the device Display Name, if java script code is inside the name of the device Display Name, its can be โ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:41 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:39 p.m.

7.5

CVSS3.1

CVE-2024-41784 - IBM Sterling Secure Proxy directory traversal

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot dot" sequences (/.../) to view arbitrary files on the system.

๐Ÿ“… Published: Nov. 15, 2024, 3:40 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:35 p.m.

4.8

CVSS3.1

CVE-2024-50352 - LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/device/overview/โ€ฆ

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated users to inject arbitrary JavaScript through the "name" parameter when adding a service to a devicโ€ฆ

๐Ÿ“… Published: Nov. 15, 2024, 3:40 p.m. ๐Ÿ”„ Last Modified: Nov. 20, 2024, 2:37 p.m.
Total resulsts: 349182
Page 7857 of 34,919
ยซ previous page ยป next page
Filters