CVE-2025-40899
- EPSS 0.03%
- Veröffentlicht 15.04.2026 08:18:36
- Zuletzt bearbeitet 17.04.2026 15:38:09
A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a Ja...
CVE-2025-40897
- EPSS 0.04%
- Veröffentlicht 15.04.2026 08:18:05
- Zuletzt bearbeitet 17.04.2026 15:38:09
An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Thre...
CVE-2025-40896
- EPSS 0.03%
- Veröffentlicht 04.03.2026 13:52:52
- Zuletzt bearbeitet 05.03.2026 18:48:12
The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result i...
CVE-2025-40895
- EPSS 0.03%
- Veröffentlicht 04.03.2026 13:52:13
- Zuletzt bearbeitet 05.03.2026 18:50:52
A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a Guardian connected to a CMC...
CVE-2025-40894
- EPSS 0.04%
- Veröffentlicht 04.03.2026 13:51:14
- Zuletzt bearbeitet 14.04.2026 10:16:27
A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML ...
CVE-2025-40898
- EPSS 0.12%
- Veröffentlicht 18.12.2025 13:19:22
- Zuletzt bearbeitet 14.04.2026 10:16:27
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can pote...
CVE-2025-40893
- EPSS 0.05%
- Veröffentlicht 18.12.2025 13:17:54
- Zuletzt bearbeitet 14.04.2026 10:16:27
A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes....
CVE-2025-40892
- EPSS 0.05%
- Veröffentlicht 18.12.2025 13:16:25
- Zuletzt bearbeitet 14.04.2026 10:16:27
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a...
CVE-2025-40891
- EPSS 0.04%
- Veröffentlicht 18.12.2025 13:14:35
- Zuletzt bearbeitet 14.04.2026 10:16:26
A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to ...
CVE-2025-40890
- EPSS 0.07%
- Veröffentlicht 25.11.2025 15:30:34
- Zuletzt bearbeitet 15.04.2026 00:35:42
A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated low-privilege user can craft a malicious dashboard containing a JavaScript payload and sh...