Nozominetworks

Cmc

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 09.07.2026 07:23:30
  • Zuletzt bearbeitet 11.08.2026 13:18:23

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, alt...

  • EPSS 0.29%
  • Veröffentlicht 09.07.2026 07:22:53
  • Zuletzt bearbeitet 11.08.2026 13:18:14

A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing ...

  • EPSS 0.24%
  • Veröffentlicht 09.07.2026 07:22:44
  • Zuletzt bearbeitet 11.08.2026 13:18:14

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH k...

  • EPSS 0.17%
  • Veröffentlicht 09.07.2026 07:22:35
  • Zuletzt bearbeitet 11.08.2026 13:18:14

An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison ...

  • EPSS 0.15%
  • Veröffentlicht 09.07.2026 07:22:21
  • Zuletzt bearbeitet 11.08.2026 13:18:14

A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags int...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:23:35
  • Zuletzt bearbeitet 09.06.2026 10:16:37

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through ...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:22:15
  • Zuletzt bearbeitet 09.06.2026 10:16:37

A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containi...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:21:02
  • Zuletzt bearbeitet 09.06.2026 10:16:37

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:19:45
  • Zuletzt bearbeitet 09.06.2026 10:16:36

A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags....

  • EPSS 0.2%
  • Veröffentlicht 19.05.2026 13:17:21
  • Zuletzt bearbeitet 09.06.2026 10:16:36

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payloa...