Libnmap is a Python library that wraps the Nmap security scanner, providing programmatic access to Nmap's network discovery and port-scanning capabilities. Its observed vulnerability surface centers on XML injection and blind XPath injection issues that arise from how the library parses Nmap's XML output. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libnmap over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16461CRITICAL A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options. | Oct 30, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-1010017HIGH libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The component is: XML Parsing. The attack vector is: Specially crafte | Jul 15, 2019 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libnmap.
Media articles that mention a CVE ID that affects a product developed by Libnmap — matched by CVE ID, not by vendor name.