Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2025-61078
Cross-site scripting (XSS) vulnerability in Request IP form in phpIPAM v1.7.3 allows remote attackers to inject arbitrary web script or HTML via the …
Phpipam
Mitigation only
MEDIUM 6.1
CVE-2024-10727
A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the applic…
Phpipam
after 1.6
MEDIUM 5.4
CVE-2024-10721
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject ma…
Phpipam
Patch available
MEDIUM 5.4
CVE-2024-10722
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scr…
Phpipam
1.7.0+
MEDIUM 5.4
CVE-2024-10723
A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject ma…
Phpipam
1.7.0+
MEDIUM 5.4
CVE-2024-10724
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when e…
Phpipam
1.7.0+
MEDIUM 5.4
CVE-2024-10725
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious …
Phpipam
1.7.0+
HIGH 7.5
CVE-2024-10718
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send th…
Phpipam
1.7.0+
MEDIUM 6.1
CVE-2024-10720
A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' sectio…
Phpipam
1.7.0+
MEDIUM 5.4
CVE-2024-10719
A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerabi…
Phpipam
1.7.0+
MEDIUM 5.9
CVE-2024-0787
phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwords for users by using the 'X…
Phpipam
1.7.0+
MEDIUM 6.1
CVE-2024-41358
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
Phpipam
Patch available
HIGH 7.1
CVE-2024-41353
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php
Phpipam
No fix yet
HIGH 7.1
CVE-2024-41354
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php
Phpipam
No fix yet
HIGH 7.1
CVE-2024-41357
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
Phpipam
No fix yet
MEDIUM 6.5
CVE-2024-41355
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
Phpipam
No fix yet
HIGH 7.5
CVE-2023-41580
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerabi…
Phpipam
1.5.2+
MEDIUM 6.1
CVE-2023-24657
phpipam v1.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the closeClass parameter at /subnet-masks/popup.php.
Phpipam
Patch available
HIGH 7.2
CVE-2023-1211
SQL Injection in GitHub repository phpipam/phpipam prior to v1.5.2.
Phpipam
1.5.2+
MEDIUM 6.1
CVE-2023-0676
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to 1.5.1.
Phpipam
1.5.1+
MEDIUM 6.1
CVE-2023-0677
Cross-site Scripting (XSS) - Reflected in GitHub repository phpipam/phpipam prior to v1.5.1.
Phpipam
1.5.1+
MEDIUM 5.3
CVE-2023-0678EPSS 37%
Missing Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
Phpipam
1.5.1+
MEDIUM 6.1
CVE-2022-3845
A vulnerability has been found in phpipam and classified as problematic. Affected by this vulnerability is an unknown functionality of the file app/a…
Phpipam
1.5.0+
CRITICAL 9.8
CVE-2022-41443
phpipam v1.5.0 was discovered to contain a header injection vulnerability via the component /admin/subnets/ripe-query.php.
Phpipam
No fix yet
MEDIUM 6.5
CVE-2022-1223
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Phpipam
1.4.6+
MEDIUM 6.5
CVE-2022-1224
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Phpipam
1.4.6+
MEDIUM 6.5
CVE-2022-1225
Incorrect Privilege Assignment in GitHub repository phpipam/phpipam prior to 1.4.6.
Phpipam
1.4.6+
MEDIUM 6.1
CVE-2021-46426
phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.
Phpipam
Patch available
HIGH 7.2
CVE-2022-23046EPSS 25%
PhpIPAM v1.4.4 allows an authenticated admin user to inject SQL sentences in the "subnet" parameter while searching a subnet via app/admin/routing/ed…
Phpipam
No fix yet
MEDIUM 6.1
CVE-2021-35438
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
Phpipam
Patch available