Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Centreon Web HIGH 8.8
CVE-2018-21023

getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.

Fix: 2.8.28 / 18.10.5+
Fix from $1,950 2019-10-08
Centreon Web HIGH 7.5
CVE-2018-21020

In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web before 2.8.27 allows attackers to bypass authenticati…

Fix: 2.8.27+
Fix from $1,950 2019-10-08
Centreon CRITICAL 9.8
CVE-2019-16194

SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/status/Services/xml/makeXMLForOn…

Fix: after 19.04.0
Fix from $2,300 2019-09-25
Centreon HIGH 8.8
CVE-2019-13024EPSS 32%

Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using t…

Patch available
Fix from $1,950 2019-07-01
Centreon HIGH 8.8
CVE-2018-19312

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.24) allows SQL Injection via the searchVM parameter to the main.php?p=20408 URI.

Fix: after 3.4.9
Fix from $1,950 2018-11-16
Centreon MEDIUM 5.4
CVE-2018-19311

Centreon 3.4.x (fixed in Centreon 18.10.0) allows XSS via the Service field to the main.php?p=20201 URI, as demonstrated by the "Monitoring > Status …

Fix: after 3.4.9
Fix from $1,600 2018-11-16
Centreon CRITICAL 9.8
CVE-2018-19281

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.

Patch available
Fix from $2,300 2018-11-14
Centreon MEDIUM 6.1
CVE-2018-19280

Centreon 3.4.x (fixed in Centreon 18.10.0) has XSS via the resource name or macro expression of a poller macro.

Fix: after 3.4.9
Fix from $1,600 2018-11-14
Centreon HIGH 8.8
CVE-2018-19271

Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.28) allows SQL Injection via the main.php searchH parameter.

Patch available
Fix from $1,950 2018-11-14
Centreon CRITICAL 9.8
CVE-2018-11587

There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.ph…

Patch available
Fix from $2,300 2018-06-25
Centreon CRITICAL 9.8
CVE-2018-11589

Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.php, the i…

Patch available
Fix from $2,300 2018-06-25
Centreon MEDIUM 5.4
CVE-2018-11588

Centreon 3.4.6 including Centreon Web 2.8.23 is vulnerable to an authenticated user injecting a payload into the username or command description, res…

Patch available
Fix from $1,600 2018-06-25
Centreon MEDIUM 5.4
CVE-2015-7672

Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).

Patch available
Fix from $1,600 2017-09-07
Centreon MEDIUM 6.5
CVE-2015-1561EPSS 9%

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed …

Fix: after 2.5.4
Fix from $1,600 2015-07-14
Centreon HIGH 7.5
CVE-2015-1560EPSS 7%

SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier …

Fix: after 2.5.4
Fix from $1,950 2015-07-14
Centreon MEDIUM 5.0
CVE-2008-1119EPSS 8%

Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a …

Fix: after 1.4.2.3
Fix from $1,600 2008-03-03
Centreon HIGH 7.5
CVE-2007-6485EPSS 11%

Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute arbitrary PHP code via a URL i…

No fix yet
Fix from $1,950 2007-12-20