Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2025-61078 Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the … Phpipam Mitigation only Fix from $1,6002025-12-09 MEDIUM 6.1 CVE-2024-10727 A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the applic… Phpipam after 1.6 Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10721 A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject ma… Phpipam Patch available Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10722 A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scr… Phpipam 1.7.0+ Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10723 A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject ma… Phpipam 1.7.0+ Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10724 A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when e… Phpipam 1.7.0+ Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10725 A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious … Phpipam 1.7.0+ Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-10718 In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send th… Phpipam 1.7.0+ Fix from $1,9502025-03-20 MEDIUM 6.1 CVE-2024-10720 A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' sectio… Phpipam 1.7.0+ Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10719 A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerabi… Phpipam 1.7.0+ Fix from $1,6002025-03-20 MEDIUM 5.9 CVE-2024-0787 phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X… Phpipam 1.7.0+ Fix from $1,6002024-11-15 MEDIUM 6.1 CVE-2024-41358 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. Phpipam Patch available Fix from $1,6002024-08-29 HIGH 7.1 CVE-2024-41353 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php Phpipam No fix yet Fix from $1,9502024-07-26 HIGH 7.1 CVE-2024-41354 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php Phpipam No fix yet Fix from $1,9502024-07-26 HIGH 7.1 CVE-2024-41357 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php. Phpipam No fix yet Fix from $1,9502024-07-26 MEDIUM 6.5 CVE-2024-41355 phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php. Phpipam No fix yet Fix from $1,6002024-07-26 HIGH 7.5 CVE-2023-41580 Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerabi… Phpipam 1.5.2+ Fix from $1,9502023-10-02 MEDIUM 6.1 CVE-2023-24657 phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php. Phpipam Patch available Fix from $1,6002023-03-08 HIGH 7.2 CVE-2023-1211 SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2. Phpipam 1.5.2+ Fix from $1,9502023-03-07 MEDIUM 6.1 CVE-2023-0676 Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1. Phpipam 1.5.1+ Fix from $1,6002023-02-04 MEDIUM 6.1 CVE-2023-0677 Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1. Phpipam 1.5.1+ Fix from $1,6002023-02-04 MEDIUM 5.3 CVE-2023-0678EPSS 37% Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1. Phpipam 1.5.1+ Fix from $1,6002023-02-04 MEDIUM 6.1 CVE-2022-3845 A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/a… Phpipam 1.5.0+ Fix from $1,6002022-11-02 CRITICAL 9.8 CVE-2022-41443 phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php. Phpipam No fix yet Fix from $2,3002022-10-03 MEDIUM 6.5 CVE-2022-1223 Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. Phpipam 1.4.6+ Fix from $1,6002022-04-04 MEDIUM 6.5 CVE-2022-1224 Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. Phpipam 1.4.6+ Fix from $1,6002022-04-04 MEDIUM 6.5 CVE-2022-1225 Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6. Phpipam 1.4.6+ Fix from $1,6002022-04-04 MEDIUM 6.1 CVE-2021-46426 phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality. Phpipam Patch available Fix from $1,6002022-03-25 HIGH 7.2 CVE-2022-23046EPSS 25% PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/ed… Phpipam No fix yet Fix from $1,9502022-01-19 MEDIUM 6.1 CVE-2021-35438 phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator. Phpipam Patch available Fix from $1,6002021-06-23