Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Icinga MEDIUM 5.5
CVE-2026-24413

Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not s…

Fix: 2.13.14 / 2.14.8+
Fix from $1,600 2026-01-29
Icinga Powershell Framework MEDIUM 5.5
CVE-2026-24414

The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versi…

Fix: 1.11.2 / 1.12.4+
Fix from $1,600 2026-01-29
Icinga MEDIUM 6.5
CVE-2025-61907

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoin…

Fix: 2.13.13 / 2.14.7+
Fix from $1,600 2025-10-16
Icinga MEDIUM 6.5
CVE-2025-61908

Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a refere…

Fix: 2.13.13 / 2.14.7+
Fix from $1,600 2025-10-16
Icinga Db Web MEDIUM 6.5
CVE-2025-61789

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use …

Fix: 1.1.4 / 1.2.3+
Fix from $1,600 2025-10-16
Icinga CRITICAL 9.8
CVE-2025-48057

Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for rep…

Fix: 2.12.12 / 2.13.12+
Fix from $2,300 2025-05-27
Icinga Web 2 MEDIUM 6.1
CVE-2025-30164

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…

Fix: 2.11.5 / 2.12.3+
Fix from $1,600 2025-03-26
Icinga Web 2 MEDIUM 5.4
CVE-2025-27609

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…

Fix: 2.11.5 / 2.12.3+
Fix from $1,600 2025-03-26
Icinga Web 2 MEDIUM 6.1
CVE-2025-27405

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…

Fix: 2.11.5 / 2.12.3+
Fix from $1,600 2025-03-26
Icinga Web 2 MEDIUM 6.1
CVE-2025-27404

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.1…

Fix: 2.11.5 / 2.12.3+
Fix from $1,600 2025-03-26
Icingaweb2 Module Incubator HIGH 8.8
CVE-2024-24819

icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base…

Fix: 0.22.0+
Fix from $1,950 2024-02-09
Icinga HIGH 8.3
CVE-2024-24820

Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate …

Fix: 1.8.2 / 1.9.2+
Fix from $1,950 2024-02-09
Icinga Web Jira Integration HIGH 8.8
CVE-2023-30607

icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configurati…

Fix: 1.3.2+
Fix from $1,950 2023-07-05
Icinga Web 2 HIGH 8.8
CVE-2022-24715EPSS 15%

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration,…

Fix: 2.8.6 / 2.9.6+
Fix from $1,950 2022-03-08
Icinga Web 2 HIGH 7.5
CVE-2022-24716EPSS 89%

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files o…

Fix: 2.9.6+
Fix from $1,950 2022-03-08
Icinga Web 2 MEDIUM 5.3
CVE-2022-24714

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled …

Fix: 2.8.6 / 2.9.6+
Fix from $1,600 2022-03-08
Icinga MEDIUM 6.5
CVE-2021-32747

Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed…

Fix: 2.7.5 / 2.8.3+
Fix from $1,600 2021-07-12
Icinga MEDIUM 5.3
CVE-2021-32746

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 and 2.8.2, the `doc` module of …

Fix: 2.7.5 / 2.8.3+
Fix from $1,600 2021-07-12
Icinga CRITICAL 9.1
CVE-2020-29663

Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. …

Fix: after 2.11.7
Fix from $2,300 2020-12-15
Icinga HIGH 7.8
CVE-2020-14004

An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/…

Fix: after 2.11.3
Fix from $1,950 2020-06-12
Icinga Web 2 CRITICAL 9.8
CVE-2018-18249

Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information …

Fix: 2.6.2+
Fix from $2,300 2018-12-17
Icinga Web 2 HIGH 7.5
CVE-2018-18250

Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation ite…

Fix: 2.6.2+
Fix from $1,950 2018-12-17
Icinga Web 2 MEDIUM 6.5
CVE-2018-18246

Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/m…

Fix: 2.6.2+
Fix from $1,600 2018-12-17
Icinga Web 2 MEDIUM 6.1
CVE-2018-18248

Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/t…

No fix yet
Fix from $1,600 2018-12-17
Icinga Web 2 MEDIUM 5.4
CVE-2018-18247

Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.

Fix: 2.6.2+
Fix from $1,600 2018-12-17
Icinga HIGH 8.1
CVE-2018-6535

An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacke…

Fix: after 2.8.1
Fix from $1,950 2018-02-27
Icinga HIGH 7.8
CVE-2018-6533

An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be us…

Fix: after 2.8.1
Fix from $1,950 2018-02-27
Icinga HIGH 7.5
CVE-2018-6532

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhau…

Fix: after 2.8.0
Fix from $1,950 2018-02-27
Icinga MEDIUM 6.5
CVE-2018-6534

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which c…

Fix: after 2.8.1
Fix from $1,600 2018-02-27
Icinga MEDIUM 5.5
CVE-2018-6536

An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which mi…

Fix: after 2.8.1
Fix from $1,600 2018-02-02