Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2023-49086
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions p…
Cacti
Patch available
HIGH 8.8
CVE-2023-49084EPSS 64%
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL …
Cacti
No fix yet
MEDIUM 6.5
CVE-2023-46490
SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers…
Cacti
No fix yet
HIGH 7.8
CVE-2023-31132
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability.…
Cacti
1.2.25+
MEDIUM 6.1
CVE-2022-48547
A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web scri…
Cacti
after 0.8.7g
MEDIUM 5.3
CVE-2022-48538
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a…
Cacti
No fix yet
MEDIUM 6.1
CVE-2022-41444
Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.
Cacti
No fix yet
HIGH 7.5
CVE-2023-37543
Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php.…
Cacti
1.2.6+
CRITICAL 9.8
CVE-2022-46169 KEVEPSS 100%
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected …
Cacti
1.2.23+
MEDIUM 6.1
CVE-2021-26247EPSS 7%
As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the Ja…
Cacti
Mitigation only
MEDIUM 5.4
CVE-2021-3816
Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a …
Cacti
Mitigation only
MEDIUM 6.1
CVE-2020-14424
Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.
Cacti
1.2.18+
MEDIUM 6.5
CVE-2019-17357EPSS 35%
Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string…
Cacti
after 1.2.7
HIGH 8.8
CVE-2020-7237EPSS 37%
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation…
Cacti
No fix yet
HIGH 8.8
CVE-2020-7058
data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. …
Cacti
No fix yet
MEDIUM 5.4
CVE-2018-20726
A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters i…
Cacti
1.2.0+
MEDIUM 5.4
CVE-2018-10059
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAM…
Cacti
after 1.1.36
HIGH 8.8
CVE-2016-10700
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging i…
Cacti
1.0.0+
HIGH 8.8
CVE-2014-4000
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized …
Cacti
1.0.0+
MEDIUM 6.1
CVE-2017-16785
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
Cacti
Patch available
HIGH 7.2
CVE-2017-16660
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then…
Cacti
Patch available
HIGH 7.2
CVE-2017-16641
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=s…
Cacti
Patch available
MEDIUM 6.1
CVE-2017-15194
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
Cacti
Patch available
MEDIUM 5.4
CVE-2017-12978
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
Cacti
after 1.1.17
MEDIUM 6.1
CVE-2017-12927
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
Cacti
Patch available
CRITICAL 9.8
CVE-2017-12065
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
Cacti
after 1.1.15
MEDIUM 5.4
CVE-2017-12066
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web scr…
Cacti
after 1.1.15
MEDIUM 5.4
CVE-2017-11691
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via speci…
Cacti
Patch available
HIGH 8.8
CVE-2017-1000031
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_tem…
Cacti
No fix yet
MEDIUM 6.1
CVE-2017-1000032
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter …
Cacti
Mitigation only