Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-49086 Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions p… Cacti Patch available Fix from $1,6002023-12-22 HIGH 8.8 CVE-2023-49084EPSS 64% Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL … Cacti No fix yet Fix from $1,9502023-12-21 MEDIUM 6.5 CVE-2023-46490 SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers… Cacti No fix yet Fix from $1,6002023-10-27 HIGH 7.8 CVE-2023-31132 Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability.… Cacti 1.2.25+ Fix from $1,9502023-09-05 MEDIUM 6.1 CVE-2022-48547 A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers to inject arbitrary web scri… Cacti after 0.8.7g Fix from $1,6002023-08-22 MEDIUM 5.3 CVE-2022-48538 In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a… Cacti No fix yet Fix from $1,6002023-08-22 MEDIUM 6.1 CVE-2022-41444 Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php. Cacti No fix yet Fix from $1,6002023-08-22 HIGH 7.5 CVE-2023-37543 Cacti before 1.2.6 allows IDOR (Insecure Direct Object Reference) for accessing any graph via a modified local_graph_id parameter to graph_xport.php.… Cacti 1.2.6+ Fix from $1,9502023-08-10 CRITICAL 9.8 CVE-2022-46169 KEVEPSS 100% Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected … Cacti 1.2.23+ Fix from $2,3002022-12-05 MEDIUM 6.1 CVE-2021-26247EPSS 7% As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the Ja… Cacti Mitigation only Fix from $1,6002022-01-19 MEDIUM 5.4 CVE-2021-3816 Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a … Cacti Mitigation only Fix from $1,6002022-01-19 MEDIUM 6.1 CVE-2020-14424 Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme. Cacti 1.2.18+ Fix from $1,6002021-11-14 MEDIUM 6.5 CVE-2019-17357EPSS 35% Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string… Cacti after 1.2.7 Fix from $1,6002020-01-21 HIGH 8.8 CVE-2020-7237EPSS 37% Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation… Cacti No fix yet Fix from $1,9502020-01-20 HIGH 8.8 CVE-2020-7058 data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. … Cacti No fix yet Fix from $1,9502020-01-15 MEDIUM 5.4 CVE-2018-20726 A cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti before 1.2.0 due to lack of escaping of unintended characters i… Cacti 1.2.0+ Fix from $1,6002019-01-16 MEDIUM 5.4 CVE-2018-10059 Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAM… Cacti after 1.1.36 Fix from $1,6002018-04-12 HIGH 8.8 CVE-2016-10700 auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging i… Cacti 1.0.0+ Fix from $1,9502017-11-24 HIGH 8.8 CVE-2014-4000 Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized … Cacti 1.0.0+ Fix from $1,9502017-11-15 MEDIUM 6.1 CVE-2017-16785 Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php. Cacti Patch available Fix from $1,6002017-11-10 HIGH 7.2 CVE-2017-16660 Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then… Cacti Patch available Fix from $1,9502017-11-08 HIGH 7.2 CVE-2017-16641 lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=s… Cacti Patch available Fix from $1,9502017-11-07 MEDIUM 6.1 CVE-2017-15194 include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page. Cacti Patch available Fix from $1,6002017-10-11 MEDIUM 5.4 CVE-2017-12978 lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user. Cacti after 1.1.17 Fix from $1,6002017-08-21 MEDIUM 6.1 CVE-2017-12927 A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php. Cacti Patch available Fix from $1,6002017-08-18 CRITICAL 9.8 CVE-2017-12065 spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter. Cacti after 1.1.15 Fix from $2,3002017-08-01 MEDIUM 5.4 CVE-2017-12066 Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web scr… Cacti after 1.1.15 Fix from $1,6002017-08-01 MEDIUM 5.4 CVE-2017-11691 Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via speci… Cacti Patch available Fix from $1,6002017-07-27 HIGH 8.8 CVE-2017-1000031 SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_tem… Cacti No fix yet Fix from $1,9502017-07-17 MEDIUM 6.1 CVE-2017-1000032 Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter … Cacti Mitigation only Fix from $1,6002017-07-17