Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cacti MEDIUM 5.4
CVE-2023-49086

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions p…

Patch available
Fix from $1,600 2023-12-22
Cacti HIGH 8.8
CVE-2023-49084EPSS 64%

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL …

No fix yet
Fix from $1,950 2023-12-21
Cacti MEDIUM 6.5
CVE-2023-46490

SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers…

No fix yet
Fix from $1,600 2023-10-27
Cacti HIGH 7.8
CVE-2023-31132

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability.…

Fix: 1.2.25+
Fix from $1,950 2023-09-05
Cacti MEDIUM 6.1
CVE-2022-48547

A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web scri…

Fix: after 0.8.7g
Fix from $1,600 2023-08-22
Cacti MEDIUM 5.3
CVE-2022-48538

In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a…

No fix yet
Fix from $1,600 2023-08-22
Cacti MEDIUM 6.1
CVE-2022-41444

Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.

No fix yet
Fix from $1,600 2023-08-22
Cacti HIGH 7.5
CVE-2023-37543

Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php.…

Fix: 1.2.6+
Fix from $1,950 2023-08-10
Cacti CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …

Fix: 1.2.23+
Fix from $2,300 2022-12-05
Cacti MEDIUM 6.1
CVE-2021-26247EPSS 7%

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the Ja…

Mitigation only
Fix from $1,600 2022-01-19
Cacti MEDIUM 5.4
CVE-2021-3816

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a …

Mitigation only
Fix from $1,600 2022-01-19
Cacti MEDIUM 6.1
CVE-2020-14424

Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.

Fix: 1.2.18+
Fix from $1,600 2021-11-14
Cacti MEDIUM 6.5
CVE-2019-17357EPSS 35%

Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string…

Fix: after 1.2.7
Fix from $1,600 2020-01-21
Cacti HIGH 8.8
CVE-2020-7237EPSS 37%

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation…

No fix yet
Fix from $1,950 2020-01-20
Cacti HIGH 8.8
CVE-2020-7058

data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. …

No fix yet
Fix from $1,950 2020-01-15
Cacti MEDIUM 5.4
CVE-2018-20726

A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters i…

Fix: 1.2.0+
Fix from $1,600 2019-01-16
Cacti MEDIUM 5.4
CVE-2018-10059

Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAM…

Fix: after 1.1.36
Fix from $1,600 2018-04-12
Cacti HIGH 8.8
CVE-2016-10700

auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging i…

Fix: 1.0.0+
Fix from $1,950 2017-11-24
Cacti HIGH 8.8
CVE-2014-4000

Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized …

Fix: 1.0.0+
Fix from $1,950 2017-11-15
Cacti MEDIUM 6.1
CVE-2017-16785

Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.

Patch available
Fix from $1,600 2017-11-10
Cacti HIGH 7.2
CVE-2017-16660

Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then…

Patch available
Fix from $1,950 2017-11-08
Cacti HIGH 7.2
CVE-2017-16641

lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=s…

Patch available
Fix from $1,950 2017-11-07
Cacti MEDIUM 6.1
CVE-2017-15194

include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.

Patch available
Fix from $1,600 2017-10-11
Cacti MEDIUM 5.4
CVE-2017-12978

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

Fix: after 1.1.17
Fix from $1,600 2017-08-21
Cacti MEDIUM 6.1
CVE-2017-12927

A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.

Patch available
Fix from $1,600 2017-08-18
Cacti CRITICAL 9.8
CVE-2017-12065

spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.

Fix: after 1.1.15
Fix from $2,300 2017-08-01
Cacti MEDIUM 5.4
CVE-2017-12066

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web scr…

Fix: after 1.1.15
Fix from $1,600 2017-08-01
Cacti MEDIUM 5.4
CVE-2017-11691

Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via speci…

Patch available
Fix from $1,600 2017-07-27
Cacti HIGH 8.8
CVE-2017-1000031

SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_tem…

No fix yet
Fix from $1,950 2017-07-17
Cacti MEDIUM 6.1
CVE-2017-1000032

Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter …

Mitigation only
Fix from $1,600 2017-07-17