Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2017-11163 Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or … Cacti Patch available Fix from $1,6002017-07-10 MEDIUM 5.4 CVE-2017-10970 Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id … Cacti Mitigation only Fix from $1,6002017-07-06 HIGH 8.8 CVE-2016-2313 auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging … Cacti after 0.8.8f Fix from $1,9502016-04-13 HIGH 8.8 CVE-2016-3172 SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the paren… Cacti after 0.8.8g Fix from $1,9502016-04-12 HIGH 8.8 CVE-2015-8604 SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execut… Cacti after 0.8.8f Fix from $1,9502016-04-11 HIGH 8.8 CVE-2016-3659 SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group… Cacti after 0.8.8g Fix from $1,9502016-04-11 HIGH 7.5 CVE-2015-8369 SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via… Cacti after 0.8.8f Fix from $1,9502015-12-17 MEDIUM 6.5 CVE-2015-8377 SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to e… Cacti after 0.8.8f Fix from $1,6002015-12-15 HIGH 7.5 CVE-2015-4634 SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id par… Cacti after 0.8.8d Fix from $1,9502015-08-11 MEDIUM 6.5 CVE-2015-0916 SQL injection vulnerability in graph.php in Cacti before 0.8.6f allows remote authenticated users to execute arbitrary SQL commands via the local_gra… Cacti after 0.8.6e Fix from $1,6002015-05-22 HIGH 7.5 CVE-2014-5261EPSS 11% The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharac… Cacti after 0.8.8b Fix from $1,9502014-08-22 HIGH 7.5 CVE-2014-5262 SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrar… Cacti after 0.8.8b Fix from $1,9502014-08-22 HIGH 7.5 CVE-2014-4644 SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via … Superlinks No fix yet Fix from $1,9502014-06-25 HIGH 7.5 CVE-2014-2708 Multiple SQL injection vulnerabilities in graph_xport.php in Cacti 0.8.7g, 0.8.8b, and earlier allow remote attackers to execute arbitrary SQL comman… Cacti Patch available Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-1435 (1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vec… Cacti Patch available Fix from $1,9502013-08-23 HIGH 7.5 CVE-2013-1434 Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary S… Cacti after 0.8.8a Fix from $1,9502013-08-23 HIGH 7.5 CVE-2011-4824 SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username… Cacti after 0.8.7g Fix from $1,9502011-12-15 MEDIUM 6.5 CVE-2010-1645 Cacti before 0.8.7f, as used in Red Hat High Performance Computing (HPC) Solution and other products, allows remote authenticated administrators to e… Cacti after 0.8.7e Fix from $1,6002010-08-23 HIGH 7.5 CVE-2010-2092 SQL injection vulnerability in graph.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via a crafted rra_id p… Cacti after 0.8.7e Fix from $1,9502010-05-27 HIGH 7.5 CVE-2010-1431 SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the exp… Cacti after 0.8.7e Fix from $1,9502010-05-04 HIGH 9.0 CVE-2009-4112EPSS 11% Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memo… Cacti after 0.8.7e Fix from $1,9502009-11-30 HIGH 7.5 CVE-2008-0785 Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL… Cacti Patch available Fix from $1,9502008-02-14 MEDIUM 5.0 CVE-2008-0784 graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id paramete… Cacti Patch available Fix from $1,6002008-02-14 HIGH 7.5 CVE-2007-6035 SQL injection vulnerability in graph.php in Cacti before 0.8.7a allows remote attackers to execute arbitrary SQL commands via the local_graph_id para… Cacti after 0.8.7 Fix from $1,9502007-11-20