Known Vulnerabilities for products from Nozominetworks
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Nozominetworks".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-40898 json | A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of ... | Not Provided | 2025-12-18 | 2026-04-14 |
| CVE-2025-40894 json | A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation ... | Not Provided | 2026-03-04 | 2026-04-14 |
| CVE-2025-40893 json | A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network tr... | Not Provided | 2025-12-18 | 2026-04-14 |
| CVE-2025-40892 json | A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an inpu... | Not Provided | 2025-12-18 | 2026-04-14 |
| CVE-2025-40891 json | A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validati... | Not Provided | 2025-12-18 | 2026-04-14 |
| CVE-2023-32649 json | A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fiel... | 7.5 - HIGH | 2023-09-19 | 2023-09-21 |
| CVE-2023-29245 json | A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in... | 7.4 - HIGH | 2023-09-19 | 2023-09-21 |
| CVE-2023-24477 json | In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do no... | 7 - HIGH | 2023-08-09 | 2023-08-15 |
| CVE-2023-24471 json | An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced i... | 6.5 - MEDIUM | 2023-08-09 | 2023-08-16 |
| CVE-2023-24015 json | A partial DoS vulnerability has been detected in the Reports section, exploitable by a malicious authenticated user forcing a... | 4.3 - MEDIUM | 2023-08-09 | 2023-08-16 |
| CVE-2023-23903 json | An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking ... | 4.9 - MEDIUM | 2023-08-09 | 2023-08-16 |
| CVE-2023-23574 json | A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count... | 6.5 - MEDIUM | 2023-08-09 | 2023-08-15 |
| CVE-2023-22843 json | An authenticated attacker with administrative access to the appliance can inject malicious JavaScript code inside the definit... | 4.8 - MEDIUM | 2023-08-09 | 2023-08-16 |
| CVE-2023-22378 json | A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting para... | 6.5 - MEDIUM | 2023-08-09 | 2023-08-15 |
| CVE-2023-2567 json | A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters use... | 6.5 - MEDIUM | 2023-09-19 | 2023-09-21 |
| CVE-2022-4259 json | Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC ... | 8.8 - HIGH | 2023-05-04 | 2023-05-10 |
| CVE-2022-0551 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2022-03-24 | 2022-03-30 |
| CVE-2022-0550 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.2 - HIGH | 2022-03-24 | 2022-03-30 |
| CVE-2021-26725 json | Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated ad... | 4.9 - MEDIUM | 2021-02-22 | 2021-02-26 |
| CVE-2021-26724 json | OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC ... | 7.2 - HIGH | 2021-02-22 | 2021-02-26 |
Known software with vulnerabilities from Nozominetworks
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Nozominetworks | Guardian | 19.0.4 |