Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-40084 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report fo… Cacti 1.2.31+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-40941 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allow… Cacti 1.2.31+ Fix from $1,6002026-06-25 HIGH 7.2 CVE-2026-40083 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+impl… Cacti 1.2.31+ Fix from $1,9502026-06-25 MEDIUM 6.1 CVE-2026-40080 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring che… Cacti 1.2.31+ Fix from $1,6002026-06-25 MEDIUM 5.4 CVE-2026-40082 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leadi… Cacti 1.2.31+ Fix from $1,6002026-06-25 CRITICAL 9.8 CVE-2026-40079 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sani… Cacti 1.2.31+ Fix from $2,3002026-06-25 HIGH 8.8 CVE-2026-39951 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph… Cacti 1.2.31+ Fix from $1,9502026-06-25 CRITICAL 9.8 CVE-2026-39938 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo… Cacti 1.2.31+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-39948 Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the … Cacti 1.2.31+ Fix from $2,3002026-06-24 CRITICAL 9.8 CVE-2026-39955 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI… Cacti 1.2.31+ Fix from $2,3002026-06-24 MEDIUM 6.1 CVE-2026-39900 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in th… Cacti 1.2.31+ Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-39899 Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter… Cacti 1.2.31+ Fix from $1,6002026-06-24 CRITICAL 9.8 CVE-2026-39893 Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into … Cacti 1.2.31+ Fix from $2,3002026-06-24 MEDIUM 6.1 CVE-2026-39897 Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_… Cacti 1.2.31+ Fix from $1,6002026-06-24 HIGH 8.8 CVE-2025-66399EPSS 11% Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configurati… Cacti 1.2.29+ Fix from $1,9502025-12-02 HIGH 8.8 CVE-2005-10004 Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbit… Cacti 0.8.6d+ Fix from $1,9502025-08-30 CRITICAL 9.8 CVE-2025-26520 Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists be… Cacti 1.2.29+ Fix from $2,3002025-02-12 HIGH 8.8 CVE-2025-24367EPSS 54% Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functiona… Cacti 1.2.29+ Fix from $1,9502025-01-27 HIGH 7.5 CVE-2025-24368 Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked an… Cacti 1.2.29+ Fix from $1,9502025-01-27 HIGH 7.2 CVE-2025-22604EPSS 5% Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject ma… Cacti 1.2.29+ Fix from $1,9502025-01-27 HIGH 8.8 CVE-2024-54145 Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of … Cacti 1.2.29+ Fix from $1,9502025-01-27 HIGH 8.8 CVE-2024-54146EPSS 41% Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_template… Cacti 1.2.29+ Fix from $1,9502025-01-27 HIGH 8.2 CVE-2024-43364EPSS 34% Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in lin… Cacti 1.2.28+ Fix from $1,9502024-10-07 HIGH 8.2 CVE-2024-43365EPSS 22% Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external l… Cacti No fix yet Fix from $1,9502024-10-07 HIGH 7.2 CVE-2024-43363EPSS 36% Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code a… Cacti 1.2.28+ Fix from $1,9502024-10-07 MEDIUM 5.4 CVE-2024-43362EPSS 35% Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `… Cacti 1.2.28+ Fix from $1,6002024-10-07 MEDIUM 5.4 CVE-2024-27082 Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site script… Cacti 1.2.27+ Fix from $1,6002024-05-14 HIGH 8.8 CVE-2023-51448EPSS 67% Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNM… Cacti No fix yet Fix from $1,9502023-12-22 MEDIUM 6.1 CVE-2023-50250 Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in vers… Cacti No fix yet Fix from $1,6002023-12-22 HIGH 8.8 CVE-2023-49085EPSS 85% Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code t… Cacti after 1.2.25 Fix from $1,9502023-12-22