Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/add/. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/{id}/edit/. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/add/. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/{id}/edit/. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/add/. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/{id}/edit/. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/add/. | |
| Modificada | Media (6.1) | 0.38% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/{id}/edit/. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/add/. | |
| Analizada | Crítica (9.3) | 0.52% | — | Honeywell Lenels2 Netbox | 30/5/2024 | 17/6/2026 | LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands. | |
| Analizada | Crítica (9.3) | 0.52% | — | Honeywell Lenels2 Netbox | 30/5/2024 | 17/6/2026 | LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an attacker to execute malicious commands with elevated permissions. | |
| Analizada | Alta (8.8) | 0.51% | — | Honeywell Lenels2 Netbox | 30/5/2024 | 17/6/2026 | LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements. | |
| Modificada | Media (6.1) | 0.53% | — | Netbox | 26/1/2024 | 17/6/2026 | ** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue affects some unknown processing of the file /core/config-revisions of the component Home Page Configuration. The manipulation with the input <<h1 onload=alert(1)>>test</h1> leads to cross site… | |
| Modificada | Media (5.4) | 0.42% | — | Netbox | 20/9/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function. | |
| Modificada | Media (5.4) | 0.70% | 💥 PoC | Netbox | 10/8/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates. | |
| Modificada | Media (5.4) | 0.39% | — | Netbox | 14/6/2023 | 17/6/2026 | Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function. | |
| Modificada | Media (5.4) | 0.39% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Media (5.4) | 0.39% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Media (5.4) | 0.39% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Media (5.4) | 0.41% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Crítica (9.1) | 0.74% | — | Netbox | 24/5/2023 | 17/6/2026 | A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects… | |
| Modificada | Media (5.4) | 0.39% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Media (5.4) | 0.41% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Tenants (/tenancy/tenants/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Media (5.4) | 0.39% | — | Netbox | 24/5/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. |