Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2024-43365EPSS 22% Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external l… Cacti No fix yet Fix from $1,9502024-10-07 HIGH 8.8 CVE-2023-51448EPSS 67% Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNM… Cacti No fix yet Fix from $1,9502023-12-22 MEDIUM 6.1 CVE-2023-50250 Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in vers… Cacti No fix yet Fix from $1,6002023-12-22 HIGH 8.8 CVE-2023-49084EPSS 64% Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL … Cacti No fix yet Fix from $1,9502023-12-21 MEDIUM 6.5 CVE-2023-46490 SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers… Cacti No fix yet Fix from $1,6002023-10-27 MEDIUM 5.3 CVE-2022-48538 In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a… Cacti No fix yet Fix from $1,6002023-08-22 MEDIUM 6.1 CVE-2022-41444 Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php. Cacti No fix yet Fix from $1,6002023-08-22 MEDIUM 6.1 CVE-2021-26247EPSS 7% As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the Ja… Cacti Mitigation only Fix from $1,6002022-01-19 MEDIUM 5.4 CVE-2021-3816 Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a … Cacti Mitigation only Fix from $1,6002022-01-19 HIGH 8.8 CVE-2020-7237EPSS 37% Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation… Cacti No fix yet Fix from $1,9502020-01-20 HIGH 8.8 CVE-2020-7058 data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. … Cacti No fix yet Fix from $1,9502020-01-15 HIGH 8.8 CVE-2017-1000031 SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_tem… Cacti No fix yet Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-1000032 Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter … Cacti Mitigation only Fix from $1,6002017-07-17 MEDIUM 5.4 CVE-2017-10970 Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id … Cacti Mitigation only Fix from $1,6002017-07-06 HIGH 7.5 CVE-2014-4644 SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via … Superlinks No fix yet Fix from $1,9502014-06-25