Known Vulnerabilities for products from Netbox Project
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Netbox Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-37625 json | A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML ... | 5.4 - MEDIUM | 2023-08-10 | 2024-02-02 |
| CVE-2023-36234 json | Cross Site Scripting (XSS) vulnerability in Netbox 3.5.1, allows attackers to execute arbitrary code via Name field in device... | 5.4 - MEDIUM | 2023-09-20 | 2024-02-02 |
| CVE-2023-34565 json | Netbox 3.5.1 is vulnerable to Cross Site Scripting (XSS) in the "Create Wireless LAN Groups" function. | 5.4 - MEDIUM | 2023-06-14 | 2024-02-02 |
| CVE-2023-33800 json | A stored cross-site scripting (XSS) vulnerability in the Create Regions (/dcim/regions/) function of Netbox v3.5.1 allows att... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33799 json | A stored cross-site scripting (XSS) vulnerability in the Create Contacts (/tenancy/contacts/) function of Netbox v3.5.1 allow... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33798 json | A stored cross-site scripting (XSS) vulnerability in the Create Rack (/dcim/rack/) function of Netbox v3.5.1 allows attackers... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33797 json | A stored cross-site scripting (XSS) vulnerability in the Create Sites (/dcim/sites/) function of Netbox v3.5.1 allows attacke... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33796 json | ** DISPUTED ** A vulnerability in Netbox v3.5.1 allows unauthenticated attackers to execute queries against the GraphQL datab... | 9.1 - CRITICAL | 2023-05-24 | 2024-02-02 |
| CVE-2023-33795 json | A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33794 json | A stored cross-site scripting (XSS) vulnerability in the Create Tenants (/tenancy/tenants/) function of Netbox v3.5.1 allows ... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33793 json | A stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 ... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33792 json | A stored cross-site scripting (XSS) vulnerability in the Create Site Groups (/dcim/site-groups/) function of Netbox v3.5.1 al... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33791 json | A stored cross-site scripting (XSS) vulnerability in the Create Provider Accounts (/circuits/provider-accounts/) function of ... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33790 json | A stored cross-site scripting (XSS) vulnerability in the Create Locations (/dcim/locations/) function of Netbox v3.5.1 allows... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33789 json | A stored cross-site scripting (XSS) vulnerability in the Create Contact Groups (/tenancy/contact-groups/) function of Netbox ... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33788 json | A stored cross-site scripting (XSS) vulnerability in the Create Providers (/circuits/providers/) function of Netbox v3.5.1 al... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33787 json | A stored cross-site scripting (XSS) vulnerability in the Create Tenant Groups (/tenancy/tenant-groups/) function of Netbox v3... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33786 json | A stored cross-site scripting (XSS) vulnerability in the Create Circuit Types (/circuits/circuit-types/) function of Netbox v... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2023-33785 json | A stored cross-site scripting (XSS) vulnerability in the Create Rack Roles (/dcim/rack-roles/) function of Netbox v3.5.1 allo... | 5.4 - MEDIUM | 2023-05-24 | 2024-02-02 |
| CVE-2019-25011 json | NetBox through 2.6.2 allows an Authenticated User to conduct an XSS attack against an admin via a GFM-rendered field, as demo... | 5.4 - MEDIUM | 2020-12-31 | 2024-02-02 |