Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability. | |
| Modificada | Alta (8.7) | 0.51% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that is recorded into audit entries, possibly… | |
| Modificada | Media (6.9) | 0.44% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the uploaded public SSH keys. | |
| Modificada | Media (5.3) | 0.31% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate… | |
| Modificada | Media (4.8) | 0.25% | — | Nozominetworks CMCNozominetworks Guardian | 9/7/2026 | 11/8/2026 | A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data through multiple input vectors. When a… | |
| Modificada | Media (5.1) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote strategy in the… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected schedule, the injected… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user,… | |
| Modificada | Media (4.8) | 0.19% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected identity, the injected… | |
| Modificada | Media (5.1) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 19/5/2026 | 17/6/2026 | An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to import a malicious… | |
| Analizada | Media (6.3) | 0.11% | — | Nozominetworks ARC | 4/3/2026 | 17/6/2026 | The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result in theft of the client token and sensitive information (such as assets… | |
| Analizada | Baja (2) | 0.18% | — | Nozominetworks CMC | 4/3/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a Guardian connected to a CMC can edit the Guardian's properties to inject HTML tags. If the Sensor… | |
| Modificada | Baja (2.1) | 0.17% | — | Nozominetworks CMCNozominetworks Guardian | 4/3/2026 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML tags. If the system is configured to use the Alerted Nodes Dashboard,… | |
| Modificada | Alta (7.2) | 0.40% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device… | |
| Modificada | Media (5.3) | 0.20% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and… | |
| Modificada | Alta (7.1) | 0.26% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 17/6/2026 | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a malicious report… | |
| Modificada | Baja (2.3) | 0.18% | — | Nozominetworks CMCNozominetworks Guardian | 18/12/2025 | 30/9/2026 | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots.… | |
| Analizada | Alta (7.2) | 0.41% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.7) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS used by the web application, potentially exposing unauthorized data, altering their structure and… | |
| Analizada | Media (6) | 0.24% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data. | |
| Analizada | Alta (7.2) | 0.27% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its… | |
| Analizada | Media (5.9) | 0.22% | — | Nozominetworks CMCNozominetworks Guardian | 7/10/2025 | 17/6/2026 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack. | |
| Aplazada | Media (5.3) | 0.21% | — | Nozominetworks CMCAI | 26/8/2025 | 17/6/2026 | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to… |