Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Eyesofnetwork CRITICAL 9.8
CVE-2022-41572

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root…

Fix: after 5.3-11
Fix from $2,300 2025-01-07
Web Interface MEDIUM 6.1
CVE-2022-41434

EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.

Mitigation only
Fix from $1,600 2022-11-08
Eyesofnetwork CRITICAL 9.8
CVE-2022-41570

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.

Fix: after 5.3-11
Fix from $2,300 2022-09-27
Eyesofnetwork CRITICAL 9.8
CVE-2022-41571

An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.

Fix: after 5.3-11
Fix from $2,300 2022-09-27
Eyesofnetwork CRITICAL 9.8
CVE-2021-40643

EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" a…

Fix: 2021-07-07+
Fix from $2,300 2022-06-30
Eyesofnetwork MEDIUM 5.4
CVE-2022-24612

An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.

No fix yet
Fix from $1,600 2022-02-25
Eyesofnetwork HIGH 8.8
CVE-2021-33525EPSS 8%

EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to…

Fix: after 5.3-11
Fix from $1,950 2021-05-24
Eyesofnetwork CRITICAL 9.8
CVE-2021-27514

EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (s…

Patch available
Fix from $2,300 2021-02-22
Eyesofnetwork HIGH 8.8
CVE-2021-27513EPSS 28%

The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre us…

Patch available
Fix from $1,950 2021-02-22
Eyesofnetwork CRITICAL 9.8
CVE-2020-27886

An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticate…

Fix: after 5.3-8
Fix from $2,300 2020-10-29
Eyesofnetwork HIGH 8.8
CVE-2020-27887

An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module…

Fix: after 5.3-8
Fix from $1,950 2020-10-29
Eyesofnetwork MEDIUM 6.1
CVE-2020-24390

eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication store…

Fix: 5.3+
Fix from $1,600 2020-08-27
Eyesofnetwork CRITICAL 9.8
CVE-2020-9465EPSS 82%

An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unaut…

Fix: 5.3-3+
Fix from $2,300 2020-02-28
Eyesofnetwork CRITICAL 9.8
CVE-2020-8656EPSS 85%

An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthenticated attacker to perform …

No fix yet
Fix from $2,300 2020-02-07
Eyesofnetwork HIGH 8.8
CVE-2020-8654EPSS 86%

An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitr…

No fix yet
Fix from $1,950 2020-02-07
Eyesofnetwork HIGH 7.8
CVE-2020-8655 KEVEPSS 60%

An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability, allowing the apache user to…

Mitigation only
Fix from $1,950 2020-02-07
Eyesofnetwork CRITICAL 9.8
CVE-2020-8657 KEVEPSS 92%

An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include/api_functions.php for API ve…

Mitigation only
Fix from $2,300 2020-02-06
Eyesofnetwork HIGH 8.8
CVE-2019-14923

EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field.

No fix yet
Fix from $1,950 2019-08-16
Eyesofnetwork HIGH 7.2
CVE-2017-16000

SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL…

No fix yet
Fix from $1,950 2017-10-29
Eyesofnetwork HIGH 7.2
CVE-2017-15933

SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute…

No fix yet
Fix from $1,950 2017-10-27
Eyesofnetwork HIGH 7.2
CVE-2017-15880

SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute…

No fix yet
Fix from $1,950 2017-10-24
Eyesofnetwork MEDIUM 5.4
CVE-2017-14984

Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary …

No fix yet
Fix from $1,600 2017-10-03
Eyesofnetwork MEDIUM 5.4
CVE-2017-14985

Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary …

No fix yet
Fix from $1,600 2017-10-03
Eyesofnetwork MEDIUM 5.4
CVE-2017-14753

Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary …

No fix yet
Fix from $1,600 2017-09-27
Eyesofnetwork CRITICAL 9.8
CVE-2017-14401

The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACC…

No fix yet
Fix from $2,300 2017-09-13
Eyesofnetwork CRITICAL 9.8
CVE-2017-14402

The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACC…

No fix yet
Fix from $2,300 2017-09-13
Eyesofnetwork CRITICAL 9.8
CVE-2017-14403

The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.

No fix yet
Fix from $2,300 2017-09-13
Eyesofnetwork HIGH 7.5
CVE-2017-14404

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_tool variable) to module/tool…

No fix yet
Fix from $1,950 2017-09-13
Eyesofnetwork HIGH 7.2
CVE-2017-14405

The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to modul…

No fix yet
Fix from $1,950 2017-09-13
Eyesofnetwork CRITICAL 9.8
CVE-2017-14247

SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.

No fix yet
Fix from $2,300 2017-09-11