Show filters
47 Total Results
Displaying 21-30 of 47
Sort by:
Attacker Value
Unknown
CVE-2024-2420
Disclosure Date: May 30, 2024 (last updated May 31, 2024)
LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker to bypass authentication requirements.
0
Attacker Value
Unknown
CVE-2024-0948
Disclosure Date: January 26, 2024 (last updated April 16, 2024)
** DISPUTED ** ** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue affects some unknown processing of the file /core/config-revisions of the component Home Page Configuration. The manipulation with the input <<h1 onload=alert(1)>>test</h1> leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The associated identifier of this vulnerability is VDB-252191. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-36234
Disclosure Date: September 20, 2023 (last updated February 25, 2025)
Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device-roles/add function.
0
Attacker Value
Unknown
CVE-2023-37625
Disclosure Date: August 10, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.
0
Attacker Value
Unknown
CVE-2023-34565
Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function.
0
Attacker Value
Unknown
CVE-2023-33800
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0
Attacker Value
Unknown
CVE-2023-33799
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0
Attacker Value
Unknown
CVE-2023-33798
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0
Attacker Value
Unknown
CVE-2023-33797
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
A stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0
Attacker Value
Unknown
CVE-2023-33796
Disclosure Date: May 24, 2023 (last updated February 03, 2024)
A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL database, granting them access to sensitive data stored in the database. NOTE: the vendor disputes this because the reporter's only query was for the schema of the API, which is public; queries for database objects would have been denied.
0