Netdisco is a network discovery and management application with a focused product footprint centered on its core inventory and visualization tool. Its vulnerability profile reflects recurring web-application input-handling weaknesses, including cross-site scripting and open-redirect flaws that are characteristic of web-facing management interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netdisco over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15810MEDIUM Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL parameter. | Sep 30, 2019 | 6.1 | 20 | NO | NO |
CVE-2023-37624MEDIUM Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking t | Jul 26, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-37623MEDIUM Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/TypeAhead.pm. | Jul 26, 2023 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netdisco.
Media articles that mention a CVE ID that affects a product developed by Netdisco — matched by CVE ID, not by vendor name.