VYPR

Netbox Community

by Netbox Community

CVEs (5)

  • CVE-2022-22986HigMar 31, 2022
    risk 0.57cvss 8.8epss 0.01

    Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.

  • CVE-2024-56917HigJun 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Netbox Community 4.1.7 is vulnerable to Cross Site Scripting (XSS) via the maintenance banner` in maintenance mode.

  • CVE-2024-56915MedJun 26, 2025
    risk 0.42cvss 6.5epss 0.00

    Netbox Community v4.1.7 and fixed in v.4.2.2 is vulnerable to Cross Site Scripting (XSS) via the RSS feed widget.

  • CVE-2024-56916MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    In Netbox Community 4.1.7, once authenticated, Configuration History > Add`is vulnerable to cross-site scripting (XSS) due to the `current value` field rendering user supplied html. An authenticated attacker can leverage this to add malicious JavaScript to the any banner field.…

  • CVE-2024-56918MedJun 24, 2025
    risk 0.40cvss 6.1epss 0.00

    In Netbox Community 4.1.7, the login page is vulnerable to cross-site scripting (XSS), which allows a privileged, authenticated attacker to exfiltrate user input from the login form.