Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Librenms MEDIUM 5.4
CVE-2024-49754EPSS 71%

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page …

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-47523

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transport…

Fix: 24.9.0+
Fix from $1,600 2024-10-01
Librenms MEDIUM 5.4
CVE-2024-47525EPSS 28%

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" fe…

Fix: 24.9.0+
Fix from $1,600 2024-10-01
Librenms MEDIUM 5.4
CVE-2024-47527

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependen…

Fix: 24.9.0+
Fix from $1,600 2024-10-01
Librenms HIGH 7.2
CVE-2024-32480EPSS 20%

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Versions prior to 24.4.0 are vulnerable to SQL injection. The `order` par…

Fix: 24.4.0+
Fix from $1,950 2024-04-22
Librenms MEDIUM 5.4
CVE-2024-32479EPSS 34%

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper sanitization on the `Service` …

Fix: 24.4.0+
Fix from $1,600 2024-04-22
Librenms HIGH 8.8
CVE-2024-32461EPSS 19%

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A SQL injection vulnerability in POST /search/search=packages in LibreNMS…

Fix: 24.4.0+
Fix from $1,950 2024-04-22
Librenms HIGH 7.5
CVE-2023-46745

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating sys…

Fix: 23.11.0+
Fix from $1,950 2023-11-17
Librenms MEDIUM 5.4
CVE-2023-48295

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating sys…

Fix: 23.11.0+
Fix from $1,600 2023-11-17
Librenms MEDIUM 6.5
CVE-2023-5591EPSS 22%

SQL Injection in GitHub repository librenms/librenms prior to 23.10.0.

Fix: after 23.9.1
Fix from $1,600 2023-10-16
Librenms MEDIUM 6.1
CVE-2023-5060

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.1.

Fix: 23.9.1+
Fix from $1,600 2023-09-19
Librenms MEDIUM 6.1
CVE-2023-4978

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Librenms MEDIUM 5.4
CVE-2023-4977

Code Injection in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Librenms MEDIUM 5.4
CVE-2023-4979

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Librenms MEDIUM 5.4
CVE-2023-4980

Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Librenms MEDIUM 5.4
CVE-2023-4981

Cross-site Scripting (XSS) - DOM in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Librenms MEDIUM 5.4
CVE-2023-4982

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 23.9.0.

Fix: 23.9.0+
Fix from $1,600 2023-09-15
Librenms MEDIUM 5.4
CVE-2023-4347EPSS 70%

Cross-site Scripting (XSS) - Reflected in GitHub repository librenms/librenms prior to 23.8.0.

Fix: 23.8.0+
Fix from $1,600 2023-08-15
Librenms CRITICAL 9.8
CVE-2022-4070

Insufficient Session Expiration in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $2,300 2022-11-20
Librenms MEDIUM 5.4
CVE-2022-4068EPSS 34%

A user is able to enable their own account if it was disabled by an admin while the user still holds a valid session. Moreover, the username is not p…

Fix: 22.10.0+
Fix from $1,600 2022-11-20
Librenms HIGH 8.8
CVE-2022-3525

Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $1,950 2022-11-20
Librenms MEDIUM 6.1
CVE-2022-3561

Cross-site Scripting (XSS) - Generic in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $1,600 2022-11-20
Librenms MEDIUM 5.4
CVE-2022-3562EPSS 94%

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $1,600 2022-11-20
Librenms MEDIUM 5.4
CVE-2022-4067EPSS 94%

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $1,600 2022-11-20
Librenms MEDIUM 6.1
CVE-2022-3516

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.10.0.

Fix: 22.10.0+
Fix from $1,600 2022-11-20
Librenms MEDIUM 5.4
CVE-2022-3231

Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.9.0.

Fix: 22.9.0+
Fix from $1,600 2022-09-17
Librenms MEDIUM 6.1
CVE-2022-36745

LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.php.

Patch available
Fix from $1,600 2022-08-30
Librenms MEDIUM 6.1
CVE-2022-36746

LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-check.inc.php.

Patch available
Fix from $1,600 2022-08-30
Librenms CRITICAL 9.8
CVE-2022-29712

LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.

Patch available
Fix from $2,300 2022-06-02
Librenms MEDIUM 6.1
CVE-2022-29711

LibreNMS v22.3.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Table/GraylogController.php.

Patch available
Fix from $1,600 2022-06-02