Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.11% | — | Netbox Device Type LibraryAI | 1/10/2026 | 2/10/2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. Prior to commit f41fc1e, the CI workflow .github/workflows/validation.yml runs on pull_request and executes code supplied by the pull request before any maintainer review. Three PR-editable files drive this:… | |
| Aplazada | Media (5.3) | 0.41% | — | Netbox Device Type LibraryAI | 17/9/2026 | 30/9/2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant that an unauthenticated pull-request author can change before the validation test… | |
| Aplazada | Alta (8.8) | 0.61% | — | Netbox Device Type LibraryAI | 17/9/2026 | 24/9/2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests directory at the front of sys.path during collection. An unauthenticated contributor… | |
| Aplazada | Crítica (9.6) | 0.66% | — | Netbox Device Type LibraryAI | 17/9/2026 | 24/9/2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the read_pickle_data function in tests/pickle_operations.py. An unauthenticated… | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | NetboxAI | 5/9/2026 | 8/9/2026 | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve plaintext passwords and secret keys for Git and Amazon S3 backends through API endpoints, gaining unauthorized access to external repositories and… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | NetboxAI | 5/9/2026 | 18/9/2026 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users with view permissions can access all users' private records through unscoped querysets, disclosing which users watch or bookmark which objects. | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | NetboxAI | 11/8/2026 | 24/9/2026 | NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only API tokens, to inject arbitrary Django ORM lookup expressions into nested object references by supplying crafted JSON dictionary keys in POST, PUT, or PATCH requests to any REST API endpoint.… | |
| Aplazada | Alta (8.7) | 1.1% | — | NetboxAI | 4/5/2026 | 17/6/2026 | NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or configtemplate permissions to execute arbitrary code by specifying malicious Python callables in the environment_params… | |
| Analizada | Media (6.1) | 0.18% | — | Netbox | 16/3/2026 | 17/6/2026 | Cross Site scripting vulnerability (XSS) in NetBox 4.3.5 "comment" field on object forms. An attacker can inject arbitrary HTML, which will be rendered in the web UI when viewed by other users. This could potentially lead to user interface redress attacks or be escalated to XSS in certain contexts. | |
| Analizada | Crítica (9.8) | 0.49% | — | Netboxlabs Netbox-docker | 11/3/2026 | 17/6/2026 | netbox-docker before 2.5.0 has a superuser account with default credentials (admin password for the admin account, and 0123456789abcdef0123456789abcdef01234567 value for SUPERUSER_API_TOKEN). In practice on the public Internet, almost all users changed the password but only about 90% changed the token. Having a… | |
| Modificada | Media (5.4) | 0.34% | — | Netbox | 3/2/2026 | 18/8/2026 | NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages without proper escaping. This allows… | |
| Analizada | Media (6.5) | 0.46% | — | Netbox | 26/6/2025 | 17/6/2026 | Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget. | |
| Analizada | Alta (7.1) | 0.39% | — | Netbox | 24/6/2025 | 17/6/2026 | Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode. | |
| Analizada | Media (6.1) | 0.32% | — | Netbox | 24/6/2025 | 17/6/2026 | In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field. Once a victim edits a Configuration… | |
| Analizada | Media (6.1) | 0.33% | — | Netbox | 24/6/2025 | 17/6/2026 | In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form. | |
| Analizada | Media (5.4) | 0.31% | — | Netbox | 22/9/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in NetBox 4.1.0 within the "Configuration History" feature of the "Admin" panel via a /core/config-revisions/ Add action. An authenticated user can inject arbitrary JavaScript or HTML into the "Top banner" field. NOTE: Multiple third parties have disputed this… | |
| Modificada | Media (6.1) | 0.45% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/add. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/{id}/edit/. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-feeds/{id}/edit/. | |
| Modificada | Media (6.1) | 0.38% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-feeds/add. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/{id}/edit/. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/add. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/add. | |
| Modificada | Media (6.1) | 0.35% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/{id}/edit/. | |
| Modificada | Media (6.1) | 0.40% | — | Netbox | 9/7/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/add/. |