CVEs we hold for Nozomi
Records whose assigning authority named Nozomi as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-33922Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0Nozomi Networks Arc
CVE-2026-33921Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0Nozomi Networks Arc
CVE-2026-33391Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0Nozomi Networks CMC
CVE-2026-33390Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0Nozomi Networks CMC
CVE-2026-33389Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc…Nozomi Networks Arc
CVE-2026-33388Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0Nozomi Networks CMC
CVE-2026-33387Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0Nozomi Networks CMC
CVE-2026-31985Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian…Nozomi Networks Remote Collector
CVE-2026-31984DoS through oversized audit log entries in Guardian/CMC before 26.2.0Nozomi Networks CMC
CVE-2026-31983Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0Nozomi Networks CMC
CVE-2026-31981HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0Nozomi Networks CMC
CVE-2025-40903HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0Nozomi Networks CMC
CVE-2025-40901HTML injection in Credentials Manager in Guardian/CMC before 26.1.0Nozomi Networks CMC
CVE-2025-40900Angular template injection in Reports in Guardian/CMC before 26.1.0Nozomi Networks CMC
CVE-2025-40899Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0Nozomi Networks CMC
CVE-2025-40898Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0Nozomi Networks CMC
CVE-2025-40897Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0Nozomi Networks CMC
CVE-2025-40896Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0Nozomi Networks Arc
CVE-2025-40894HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0Nozomi Networks CMC
CVE-2025-40892Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0Nozomi Networks CMC
CVE-2025-40891HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0Nozomi Networks CMC
CVE-2025-40890Stored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0Nozomi Networks CMC
CVE-2025-40889Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0Nozomi Networks CMC
CVE-2025-40888Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0Nozomi Networks CMC
CVE-2025-40887Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0Nozomi Networks CMC
CVE-2025-40886Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0Nozomi Networks CMC
CVE-2025-40885Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0Nozomi Networks CMC
CVE-2025-1501Incorrect authorization for traces request/download in CMC before 25.1.0Nozomi Networks CMC
CVE-2024-4465Incorrect authorization for Reports configuration in Guardian/CMC before 24.2.0Nozomi Networks CMC
CVE-2024-13089Authenticated RCE in update functionality in Guardian/CMC before 24.6.0Nozomi Networks CMC
CVE-2024-0218DoS on IDS parsing of malformed Radius packets in Guardian before 23.4.1Nozomi Networks Guardian
CVE-2023-6916Information disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1Nozomi Networks CMC
CVE-2023-5937Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0Nozomi Networks Arc
CVE-2023-5936Unsafe temporary data privileges on Unix systems in Arc before v1.6.0Nozomi Networks Arc
CVE-2023-5253Check Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0Nozomi Networks CMC
CVE-2023-32649DoS on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0Nozomi Networks CMC
CVE-2023-29245SQL Injection on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0Nozomi Networks CMC
CVE-2023-2567Authenticated SQL Injection on Query functionality in Guardian/CMC before 22.6.3 and 23.1.0Nozomi Networks CMC
CVE-2023-24471Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2Nozomi Networks CMC
CVE-2023-24015Partial DoS on Reports section due to null report name in Guardian/CMC before 22.6.2Nozomi Networks CMC
CVE-2023-23574Authenticated Blind SQL Injection on alerts count in Guardian/CMC before 22.6.2Nozomi Networks CMC
CVE-2023-22843Stored Cross-Site Scripting (XSS) in Threat Intelligence rules in Guardian/CMC before 22.6.2Nozomi Networks CMC
CVE-2023-22378Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2Nozomi Networks CMC
CVE-2022-4259Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2Nozomi Networks Guardian
CVE-2022-0551Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0Nozomi Networks CMC
CVE-2022-0550Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0Nozomi Networks CMC
CVE-2021-26725Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4Nozomi Networks CMC
CVE-2021-26724Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4Nozomi Networks CMC
61 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.