Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cmc HIGH 8.1
CVE-2026-33390

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An …

Fix: 26.2.0+
Fix from $1,950 2026-07-09
Cmc HIGH 7.5
CVE-2026-31984

A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size li…

Fix: 26.2.0+
Fix from $1,950 2026-07-09
Cmc HIGH 7.1
CVE-2026-31982

An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirectio…

Fix: 26.2.0+
Fix from $1,950 2026-07-09
Cmc MEDIUM 5.3
CVE-2026-31983

A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the…

Fix: 26.2.0+
Fix from $1,600 2026-07-09
Cmc MEDIUM 5.4
CVE-2025-40904

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenti…

Fix: 26.1.0+
Fix from $1,600 2026-05-19
Cmc MEDIUM 5.4
CVE-2025-40894

A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. …

Fix: 25.6.0+
Fix from $1,600 2026-03-04
Cmc HIGH 8.9
CVE-2025-40892

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenti…

Fix: 25.5.0+
Fix from $1,950 2025-12-18
Cmc HIGH 8.1
CVE-2025-40898

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authe…

Fix: 25.5.0+
Fix from $1,950 2025-12-18
Cmc MEDIUM 6.1
CVE-2025-40893

A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthent…

Fix: 25.5.0+
Fix from $1,600 2025-12-18
Cmc HIGH 8.1
CVE-2025-40889

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated u…

Fix: 25.2.0+
Fix from $1,950 2025-10-07
Cmc HIGH 8.8
CVE-2025-40886

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with …

Fix: 25.2.0+
Fix from $1,950 2025-10-07
Cmc MEDIUM 6.5
CVE-2025-40885

A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated us…

Fix: 25.2.0+
Fix from $1,600 2025-10-07
Cmc MEDIUM 6.5
CVE-2025-40887

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with …

Fix: 25.2.0+
Fix from $1,600 2025-10-07
Cmc MEDIUM 6.5
CVE-2025-40888

A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with li…

Fix: 25.3.0+
Fix from $1,600 2025-10-07
Cmc HIGH 8.1
CVE-2025-3719

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users wi…

Fix: 25.2.0+
Fix from $1,950 2025-10-07
Cmc MEDIUM 5.4
CVE-2025-3718

A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. …

Fix: 25.2.0+
Fix from $1,600 2025-10-07
Cmc MEDIUM 5.0
CVE-2024-4465

An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with…

Fix: 24.2.0+
Fix from $1,600 2024-09-11
Cmc HIGH 7.5
CVE-2023-5253

A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an un…

Fix: 23.3.0+
Fix from $1,950 2024-01-15
Cmc HIGH 7.5
CVE-2023-32649

A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Int…

Fix: 22.6.3 / 23.1.0+
Fix from $1,950 2023-09-19
Cmc HIGH 8.8
CVE-2023-2567

A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the …

Fix: 22.6.3 / 23.1.0+
Fix from $1,950 2023-09-19
Cmc HIGH 7.4
CVE-2023-29245

A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence …

Fix: 22.6.3 / 23.1.0+
Fix from $1,950 2023-09-19
Cmc HIGH 8.8
CVE-2023-23574

A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an au…

Fix: 22.6.2+
Fix from $1,950 2023-08-09
Cmc MEDIUM 6.5
CVE-2023-22378

A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authent…

Fix: 22.6.2+
Fix from $1,600 2023-08-09
Cmc MEDIUM 6.5
CVE-2023-24471

An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functional…

Fix: 22.6.2+
Fix from $1,600 2023-08-09
Cmc HIGH 7.0
CVE-2023-24477

In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely inva…

Fix: 22.6.2+
Fix from $1,950 2023-08-09
Cmc HIGH 8.8
CVE-2022-4259

Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated …

Fix: 22.5.2+
Fix from $1,950 2023-05-04
Cmc HIGH 7.2
CVE-2022-0550

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin…

Fix: 22.0.0+
Fix from $1,950 2022-03-24
Cmc HIGH 7.2
CVE-2022-0551

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or imp…

Fix: 22.0.0+
Fix from $1,950 2022-03-24
Central Management Control HIGH 7.2
CVE-2021-26724

OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated adm…

Fix: 19.0.12 / 20.0.7.4+
Fix from $1,950 2021-02-22
Guardian HIGH 7.3
CVE-2020-7049

Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.

Fix: 19.0.4+
Fix from $1,950 2020-06-30