CVE-2026-107510
- EPSS 0.29%
- Veröffentlicht 08.10.2026 09:45:04
- Zuletzt bearbeitet 09.10.2026 07:17:18
An authenticated high privilege user can inject arguments in troubleshooting commands resulting in privilege escalation.
CVE-2025-61880
- EPSS 0.57%
- Veröffentlicht 12.02.2026 00:00:00
- Zuletzt bearbeitet 19.02.2026 15:55:38
In Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.
CVE-2025-61879
- EPSS 0.26%
- Veröffentlicht 12.02.2026 00:00:00
- Zuletzt bearbeitet 19.02.2026 15:55:56
In Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.
CVE-2024-36047
- EPSS 0.43%
- Veröffentlicht 27.02.2025 23:15:37
- Zuletzt bearbeitet 10.04.2025 16:46:54
Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
CVE-2024-37566
- EPSS 0.44%
- Veröffentlicht 27.02.2025 23:15:37
- Zuletzt bearbeitet 10.04.2025 16:45:21
Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
CVE-2024-37567
- EPSS 0.34%
- Veröffentlicht 27.02.2025 23:15:37
- Zuletzt bearbeitet 10.04.2025 16:45:23
Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
CVE-2024-36046
- EPSS 0.39%
- Veröffentlicht 27.02.2025 23:15:36
- Zuletzt bearbeitet 10.04.2025 20:14:10
Infoblox NIOS through 8.6.4 executes with more privileges than required.
CVE-2022-28975
- EPSS 0.35%
- Veröffentlicht 09.01.2024 14:15:45
- Zuletzt bearbeitet 09.07.2026 01:17:26
A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the VLAN View Name field.
CVE-2023-37249
- EPSS 0.6%
- Veröffentlicht 25.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:11:18
Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.
CVE-2020-15303
- EPSS 0.86%
- Veröffentlicht 28.06.2021 13:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:16
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.