Show filters
47 Total Results
Displaying 21-30 of 47
Sort by:
Attacker Value
Unknown

CVE-2024-2420

Disclosure Date: May 30, 2024 (last updated May 31, 2024)
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
0
Attacker Value
Unknown

CVE-2024-0948

Disclosure Date: January 26, 2024 (last updated April 16, 2024)
** DISPUTED ** ** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue affects some unknown processing of the file /core/config-revisions of the component Home Page Configuration. The manipulation with the input <<h1 onload=alert(1)>>test</h1> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-252191. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-36234

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function.
Attacker Value
Unknown

CVE-2023-37625

Disclosure Date: August 10, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.
Attacker Value
Unknown

CVE-2023-34565

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function.
Attacker Value
Unknown

CVE-2023-33800

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2023-33799

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2023-33798

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2023-33797

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
Attacker Value
Unknown

CVE-2023-33796

Disclosure Date: May 24, 2023 (last updated February 03, 2024)
A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects would have been denied.