Vulnerability index

Browse CVEs

31 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-33390 An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An … Cmc 26.2.0+ Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-31984 A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size li… Cmc 26.2.0+ Fix from $1,9502026-07-09 HIGH 7.1 CVE-2026-31982 An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirectio… Cmc 26.2.0+ Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-31983 A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the… Cmc 26.2.0+ Fix from $1,6002026-07-09 MEDIUM 5.4 CVE-2025-40904 A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenti… Cmc 26.1.0+ Fix from $1,6002026-05-19 MEDIUM 5.4 CVE-2025-40894 A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. … Cmc 25.6.0+ Fix from $1,6002026-03-04 HIGH 8.9 CVE-2025-40892 A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenti… Cmc 25.5.0+ Fix from $1,9502025-12-18 HIGH 8.1 CVE-2025-40898 A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authe… Cmc 25.5.0+ Fix from $1,9502025-12-18 MEDIUM 6.1 CVE-2025-40893 A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthent… Cmc 25.5.0+ Fix from $1,6002025-12-18 HIGH 8.1 CVE-2025-40889 A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated u… Cmc 25.2.0+ Fix from $1,9502025-10-07 HIGH 8.8 CVE-2025-40886 A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with … Cmc 25.2.0+ Fix from $1,9502025-10-07 MEDIUM 6.5 CVE-2025-40885 A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated us… Cmc 25.2.0+ Fix from $1,6002025-10-07 MEDIUM 6.5 CVE-2025-40887 A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with … Cmc 25.2.0+ Fix from $1,6002025-10-07 MEDIUM 6.5 CVE-2025-40888 A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with li… Cmc 25.3.0+ Fix from $1,6002025-10-07 HIGH 8.1 CVE-2025-3719 An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users wi… Cmc 25.2.0+ Fix from $1,9502025-10-07 MEDIUM 5.4 CVE-2025-3718 A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. … Cmc 25.2.0+ Fix from $1,6002025-10-07 MEDIUM 5.0 CVE-2024-4465 An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with… Cmc 24.2.0+ Fix from $1,6002024-09-11 HIGH 7.5 CVE-2023-5253 A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an un… Cmc 23.3.0+ Fix from $1,9502024-01-15 HIGH 7.5 CVE-2023-32649 A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Int… Cmc 22.6.3 / 23.1.0+ Fix from $1,9502023-09-19 HIGH 8.8 CVE-2023-2567 A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the … Cmc 22.6.3 / 23.1.0+ Fix from $1,9502023-09-19 HIGH 7.4 CVE-2023-29245 A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence … Cmc 22.6.3 / 23.1.0+ Fix from $1,9502023-09-19 HIGH 8.8 CVE-2023-23574 A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an au… Cmc 22.6.2+ Fix from $1,9502023-08-09 MEDIUM 6.5 CVE-2023-22378 A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authent… Cmc 22.6.2+ Fix from $1,6002023-08-09 MEDIUM 6.5 CVE-2023-24471 An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functional… Cmc 22.6.2+ Fix from $1,6002023-08-09 HIGH 7.0 CVE-2023-24477 In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely inva… Cmc 22.6.2+ Fix from $1,9502023-08-09 HIGH 8.8 CVE-2022-4259 Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated … Cmc 22.5.2+ Fix from $1,9502023-05-04 HIGH 7.2 CVE-2022-0550 Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin… Cmc 22.0.0+ Fix from $1,9502022-03-24 HIGH 7.2 CVE-2022-0551 Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or imp… Cmc 22.0.0+ Fix from $1,9502022-03-24 HIGH 7.2 CVE-2021-26724 OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated adm… Central Management Control 19.0.12 / 20.0.7.4+ Fix from $1,9502021-02-22 HIGH 7.3 CVE-2020-7049 Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. Guardian 19.0.4+ Fix from $1,9502020-06-30