Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Librenms MEDIUM 5.4
CVE-2022-0589

Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.

Fix: 22.1.0+
Fix from $1,600 2022-02-15
Librenms MEDIUM 6.5
CVE-2022-0587

Improper Authorization in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,600 2022-02-15
Librenms MEDIUM 6.5
CVE-2022-0588

Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,600 2022-02-15
Librenms HIGH 8.8
CVE-2022-0580

Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,950 2022-02-14
Librenms MEDIUM 6.1
CVE-2022-0576

Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms prior to 22.1.0.

Fix: 22.2.0+
Fix from $1,600 2022-02-14
Librenms MEDIUM 5.4
CVE-2022-0575

Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.2.0.

Fix: 22.2.0+
Fix from $1,600 2022-02-14
Librenms CRITICAL 9.8
CVE-2021-44278

Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.

Patch available
Fix from $2,300 2021-12-03
Librenms MEDIUM 6.1
CVE-2021-44277

Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/common/alert-log.inc.php.

Patch available
Fix from $1,600 2021-12-01
Librenms MEDIUM 6.1
CVE-2021-44279

Librenms 21.11.0 is affected by a Cross Site Scripting (XSS) vulnerability in includes/html/forms/poller-groups.inc.php.

Patch available
Fix from $1,600 2021-12-01
Librenms MEDIUM 6.1
CVE-2021-43324

LibreNMS through 21.10.2 allows XSS via a widget title.

Fix: after 21.10.2
Fix from $1,600 2021-11-03
Librenms MEDIUM 5.4
CVE-2021-31274

In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization of the $api->description vari…

Fix: 21.3.0+
Fix from $1,600 2021-09-08
Librenms HIGH 8.8
CVE-2020-35700

A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allows remote…

Fix: 21.1.0+
Fix from $1,950 2021-02-08
Librenms HIGH 8.8
CVE-2020-15877

An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'" instead of "'m…

Fix: 1.65.1+
Fix from $1,950 2020-07-21
Librenms MEDIUM 6.5
CVE-2020-15873

In LibreNMS before 1.65.1, an authenticated attacker can achieve SQL Injection via the customoid.inc.php device_id POST parameter to ajax_form.php.

Fix: 1.65.1+
Fix from $1,600 2020-07-21
Librenms HIGH 8.8
CVE-2019-10671

An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injectio…

Fix: after 1.47
Fix from $1,950 2019-09-09
Librenms HIGH 8.8
CVE-2019-12463

An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/gr…

Fix: 1.53+
Fix from $1,950 2019-09-09
Librenms HIGH 8.1
CVE-2019-12465

An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used ins…

Fix: 1.53+
Fix from $1,950 2019-09-09
Librenms HIGH 7.5
CVE-2019-12464

An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /pdf.php file with a partial f…

No fix yet
Fix from $1,950 2019-09-09
Librenms MEDIUM 6.1
CVE-2019-10670

An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for filtering data. However, thi…

Fix: after 1.47
Fix from $1,600 2019-09-09
Librenms CRITICAL 9.8
CVE-2019-10665

An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes…

Fix: after 1.47
Fix from $2,300 2019-09-09
Librenms CRITICAL 9.1
CVE-2019-10668

An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authenticatio…

Fix: after 1.47
Fix from $2,300 2019-09-09
Librenms HIGH 8.1
CVE-2019-10666

An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied…

Fix: after 1.47
Fix from $1,950 2019-09-09
Librenms HIGH 7.2
CVE-2019-10669EPSS 81%

An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/device/collectd.inc.php where us…

Fix: after 1.47
Fix from $1,950 2019-09-09
Librenms MEDIUM 5.3
CVE-2019-10667

An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exact code version installed and …

Fix: after 1.47
Fix from $1,600 2019-09-09
Librenms MEDIUM 5.4
CVE-2019-15230

LibreNMS v1.54 has XSS in the Create User, Inventory, Add Device, Notifications, Alert Rule, Create Maintenance, and Alert Template sections of the a…

No fix yet
Fix from $1,600 2019-08-28
Librenms CRITICAL 9.8
CVE-2018-20434EPSS 71%

LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php durin…

No fix yet
Fix from $2,300 2019-04-24
Librenms HIGH 8.8
CVE-2018-20678

LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a search.

Fix: after 1.47
Fix from $1,950 2019-03-28
Librenms MEDIUM 6.1
CVE-2018-18478

Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_…

Fix: 1.44+
Fix from $1,600 2018-10-18
Librenms MEDIUM 5.9
CVE-2017-16759

The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.

Fix: after 1.30
Fix from $1,600 2017-11-09