Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Centreon Host Monitoring Widget MEDIUM 6.1
CVE-2020-13628

Cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the widgetId parameter to host-monitoring…

Fix: 1.0.3 / 1.6.4+
Fix from $1,600 2020-05-27
Centreon HIGH 8.8
CVE-2020-13252EPSS 5%

Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a m…

Fix: 19.04.15+
Fix from $1,950 2020-05-21
Centreon HIGH 7.2
CVE-2019-19699EPSS 28%

There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers misconfiguration, leading to sy…

Fix: after 19.10
Fix from $1,950 2020-04-06
Centreon HIGH 8.8
CVE-2019-19487EPSS 5%

Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.

Fix: after 19.04.4
Fix from $1,950 2020-03-20
Centreon MEDIUM 6.5
CVE-2019-19486

Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test.

Fix: after 19.04.4
Fix from $1,600 2020-03-20
Centreon MEDIUM 6.1
CVE-2019-19484

Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and execute unintended behavior.

Fix: after 19.04.4
Fix from $1,600 2020-03-20
Centreon CRITICAL 9.8
CVE-2019-17647

An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2. SQL Injection exists via the include/monitoring/status/Hosts/xml/ho…

Fix: 2.8.30 / 18.10.8+
Fix from $2,300 2020-03-05
Centreon HIGH 7.5
CVE-2019-17646

An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for…

Fix: 18.10.8 / 19.04.5+
Fix from $1,950 2020-03-05
Centreon HIGH 8.8
CVE-2019-17642

An issue was discovered in Centreon before 18.10.8, 19.10.1, and 19.04.2. It allows CSRF with resultant remote command execution via shell metacharac…

Fix: 18.10.8 / 19.04.2+
Fix from $1,950 2020-03-05
Centreon HIGH 7.5
CVE-2019-17645

An issue was discovered in Centreon before 2.8.31, 18.10.9, 19.04.6, and 19.10.3. It provides sensitive information via an unauthenticated direct req…

Fix: 2.8.31 / 18.10.9+
Fix from $1,950 2020-03-05
Centreon HIGH 7.5
CVE-2019-17643

An issue was discovered in Centreon before 2.8-30,18.10-8, 19.04-5, and 19.10-2. It provides sensitive information via an unauthenticated direct requ…

Fix: 2.8.30 / 18.10.8+
Fix from $1,950 2020-03-04
Centreon HIGH 7.5
CVE-2019-17644

An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct re…

Fix: 2.8.30 / 18.10.8+
Fix from $1,950 2020-03-04
Centreon HIGH 8.8
CVE-2020-9463

Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an …

No fix yet
Fix from $1,950 2020-02-28
Centreon Web HIGH 8.8
CVE-2019-15299

An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the…

Fix: after 19.04.3
Fix from $1,950 2020-02-24
Centreon HIGH 7.8
CVE-2019-20327

Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrappe…

Fix: after 19.10
Fix from $1,950 2020-01-16
Centreon Web HIGH 8.8
CVE-2019-15298EPSS 27%

A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/configuration/configObject/tra…

Fix: 2.8.30 / 18.10.8+
Fix from $1,950 2019-11-27
Centreon Web HIGH 8.8
CVE-2019-15300

A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Administration/parameters/ldap/xml…

Fix: 2.8.30 / 19.04.5+
Fix from $1,950 2019-11-27
Centreon MEDIUM 6.1
CVE-2019-16195

Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.

Fix: 2.8.30 / 18.10.8+
Fix from $1,600 2019-11-26
Centreon Web HIGH 7.8
CVE-2019-16406

Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attack…

Patch available
Fix from $1,950 2019-11-21
Centreon Web HIGH 7.2
CVE-2019-16405EPSS 27%

Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrato…

Fix: 2.8.30 / 18.10.8+
Fix from $1,950 2019-11-21
Centreon HIGH 8.8
CVE-2019-17501

Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (aka the Configuration > Comma…

No fix yet
Fix from $1,950 2019-10-14
Centreon Web MEDIUM 5.3
CVE-2019-17105

The token generator in index.php in Centreon Web before 2.8.27 is predictable.

Fix: 2.8.27 / 18.10.5+
Fix from $1,600 2019-10-08
Centreon CRITICAL 9.8
CVE-2018-21024

licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.

Fix: 2.8.27+
Fix from $2,300 2019-10-08
Centreon Web HIGH 8.8
CVE-2019-17107

minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE…

Fix: 2.8.27 / 18.10.4+
Fix from $1,950 2019-10-08
Centreon Vm HIGH 7.5
CVE-2019-17104

In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft because the HTTPOnly flag is no…

Fix: after 19.04.3
Fix from $1,950 2019-10-08
Centreon Web MEDIUM 6.5
CVE-2019-17106

In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.

Fix: after 2.8.29
Fix from $1,600 2019-10-08
Centreon Web MEDIUM 6.1
CVE-2019-17108

Local file inclusion in brokerPerformance.php in Centreon Web before 2.8.28 allows attackers to disclose information or perform a stored XSS attack o…

Fix: 2.8.28 / 18.10.5+
Fix from $1,600 2019-10-08
Centreon Vm CRITICAL 9.8
CVE-2018-21025

In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configura…

Fix: after 19.04.3
Fix from $2,300 2019-10-08
Centreon Web HIGH 8.8
CVE-2018-21021

img_gantt.php in Centreon Web before 2.8.27 allows attackers to perform SQL injections via the host_id parameter.

Fix: 2.8.27+
Fix from $1,950 2019-10-08
Centreon Web HIGH 8.8
CVE-2018-21022

makeXML_ListServices.php in Centreon Web before 2.8.28 allows attackers to perform SQL injections via the host_id parameter.

Fix: 2.8.28+
Fix from $1,950 2019-10-08