N

Nozominetworks Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Nozominetworks products.

9 known CVE vulnerabilities tracked

Critical
0
High
2
Medium
7
Low
0
None
0

Vulnerabilities By Year

Products Affected

All Nozominetworks CVEs

CVE-2025-40904
6.5 medium

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote

Cmc May 19, 2026
CVE-2025-40903
5.9 medium

A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected sch

Cmc May 19, 2026
CVE-2025-40902
5.9 medium

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing th

Cmc May 19, 2026
CVE-2025-40901
5.9 medium

A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected ide

Cmc May 19, 2026
CVE-2025-40900
4.6 medium

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be socially engineered to impor

Cmc May 19, 2026
CVE-2025-40898
8.1 high

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths,

Cmc Dec 18, 2025
CVE-2025-40893
6.1 medium

A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the As

Cmc Dec 18, 2025
CVE-2025-40892
8.9 high

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing a JavaScript payload, or a victim can be socially engineered to import a mal

Cmc Dec 18, 2025
CVE-2025-40891
4.7 medium

A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two

Cmc Dec 18, 2025