Products: 4
    Vulnerabilities: 16
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    8
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-26961

    Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

    Last Modified: Sep 10, 2026
    Published: Sep 04, 2026

    CVE-2024-28803

    Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter

    Last Modified: Oct 14, 2025
    Published: Mar 13, 2025

    CVE-2024-31842

    An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be saved in the browser's history, passed through Referers to other web sites, stored in web logs, or otherwise recorded in other sources. If the query string contains sensitive information such as session identifiers, then attackers can use this information to launch further attacks. Because the access token in sent in GET requests, this vulnerability could lead to complete account takeover.

    Last Modified: Oct 29, 2024
    Published: Aug 20, 2024

    CVE-2024-28804

    An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.

    Last Modified: Oct 14, 2025
    Published: Jul 29, 2024

    CVE-2024-28805

    An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

    Last Modified: Oct 14, 2025
    Published: Jul 29, 2024
    Items Per Page