Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cacti MEDIUM 5.4
CVE-2017-11163

Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or …

Patch available
Fix from $1,600 2017-07-10
Cacti MEDIUM 5.4
CVE-2017-10970

Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id …

Mitigation only
Fix from $1,600 2017-07-06
Cacti HIGH 8.8
CVE-2016-2313

auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging …

Fix: after 0.8.8f
Fix from $1,950 2016-04-13
Cacti HIGH 8.8
CVE-2016-3172

SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the paren…

Fix: after 0.8.8g
Fix from $1,950 2016-04-12
Cacti HIGH 8.8
CVE-2015-8604

SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execut…

Fix: after 0.8.8f
Fix from $1,950 2016-04-11
Cacti HIGH 8.8
CVE-2016-3659

SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group…

Fix: after 0.8.8g
Fix from $1,950 2016-04-11
Cacti HIGH 7.5
CVE-2015-8369

SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via…

Fix: after 0.8.8f
Fix from $1,950 2015-12-17
Cacti MEDIUM 6.5
CVE-2015-8377

SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to e…

Fix: after 0.8.8f
Fix from $1,600 2015-12-15
Cacti HIGH 7.5
CVE-2015-4634

SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id par…

Fix: after 0.8.8d
Fix from $1,950 2015-08-11
Cacti MEDIUM 6.5
CVE-2015-0916

SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_gra…

Fix: after 0.8.6e
Fix from $1,600 2015-05-22
Cacti HIGH 7.5
CVE-2014-5261EPSS 11%

The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharac…

Fix: after 0.8.8b
Fix from $1,950 2014-08-22
Cacti HIGH 7.5
CVE-2014-5262

SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrar…

Fix: after 0.8.8b
Fix from $1,950 2014-08-22
Superlinks HIGH 7.5
CVE-2014-4644

SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via …

No fix yet
Fix from $1,950 2014-06-25
Cacti HIGH 7.5
CVE-2014-2708

Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL comman…

Patch available
Fix from $1,950 2014-04-10
Cacti HIGH 7.5
CVE-2013-1435

(1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vec…

Patch available
Fix from $1,950 2013-08-23
Cacti HIGH 7.5
CVE-2013-1434

Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary S…

Fix: after 0.8.8a
Fix from $1,950 2013-08-23
Cacti HIGH 7.5
CVE-2011-4824

SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username…

Fix: after 0.8.7g
Fix from $1,950 2011-12-15
Cacti MEDIUM 6.5
CVE-2010-1645

Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to e…

Fix: after 0.8.7e
Fix from $1,600 2010-08-23
Cacti HIGH 7.5
CVE-2010-2092

SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id p…

Fix: after 0.8.7e
Fix from $1,950 2010-05-27
Cacti HIGH 7.5
CVE-2010-1431

SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the exp…

Fix: after 0.8.7e
Fix from $1,950 2010-05-04
Cacti HIGH 9.0
CVE-2009-4112EPSS 11%

Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memo…

Fix: after 0.8.7e
Fix from $1,950 2009-11-30
Cacti HIGH 7.5
CVE-2008-0785

Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL…

Patch available
Fix from $1,950 2008-02-14
Cacti MEDIUM 5.0
CVE-2008-0784

graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id paramete…

Patch available
Fix from $1,600 2008-02-14
Cacti HIGH 7.5
CVE-2007-6035

SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id para…

Fix: after 0.8.7
Fix from $1,950 2007-11-20