Security Advisories 2025

15 advisories were published in this year.

NN-2025:14-01 | 2025-12-18 | Last update: 2025-12-18

HTML injection in Asset List in Guardian/CMC before 25.5.0

NN-2025:13-01 | 2025-12-18 | Last update: 2025-12-18

Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0

NN-2025:12-01 | 2025-12-18 | Last update: 2025-12-18

HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0

NN-2025:11-01 | 2025-11-25 | Last update: 2025-11-26

Stored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0

NN-2025:10-01 | 2025-10-07 | Last update: 2025-10-07

Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0

NN-2025:9-01 | 2025-10-07 | Last update: 2025-10-07

Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0

NN-2025:5-01 | 2025-10-07 | Last update: 2025-10-07

Incorrect authorization for CLI in Guardian/CMC before 25.2.0

NN-2025:4-01 | 2025-10-07 | Last update: 2025-10-07

Client-side path traversal in Guardian/CMC before 25.2.0

NN-2025:3-01 | 2025-08-26 | Last update: 2025-08-26

Incorrect authorization for traces request/download in CMC before 25.1.0

NN-2025:2-01 | 2025-06-10 | Last update: 2025-06-10

Privilege escalation in Guardian/CMC before 24.6.0

NN-2025:1-01 | 2025-06-10 | Last update: 2025-06-10

Authenticated RCE in update functionality in Guardian/CMC before 24.6.0