Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2018-25063
A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of th…
Dashboard
1.3.5+
HIGH 7.8
CVE-2019-14257
pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka Z…
Zenoss
No fix yet
HIGH 7.5
CVE-2019-14258
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
Zenoss
No fix yet
MEDIUM 6.8
CVE-2014-9386
Zenoss Core before 4.2.5 SP161 sets an infinite lifetime for the session ID cookie, which makes it easier for remote attackers to hijack sessions by …
Zenoss Core
after 4.2.5
MEDIUM 6.8
CVE-2014-9385
Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary use…
Zenoss Core
Mitigation only
MEDIUM 5.0
CVE-2014-9251
Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext value…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-9250
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remot…
Zenoss Core
after 5.0.0
HIGH 7.5
CVE-2014-9249
The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open po…
Zenoss Core
after 4.2.5
MEDIUM 5.0
CVE-2014-9248
Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-force attack…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-9245
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name a…
Zenoss Core
after 5.0.0
HIGH 9.3
CVE-2014-6261EPSS 20%
Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1…
Zenoss Core
after 5.0.0
MEDIUM 6.8
CVE-2014-6260
Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary c…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-6259
Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-6258
An unspecified endpoint in Zenoss Core through 5 Beta 3 allows remote attackers to cause a denial of service (CPU consumption) by triggering an arbit…
Zenoss Core
after 5.0.0
MEDIUM 5.0
CVE-2014-6257
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper me…
Zenoss Core
after 5.0.0
HIGH 7.5
CVE-2014-6256
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2…
Zenoss Core
after 5.0.0
MEDIUM 6.4
CVE-2014-6255
Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and …
Zenoss Core
after 4.2.5
MEDIUM 6.8
CVE-2014-6253
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arb…
Zenoss Core
after 5.0.0
MEDIUM 5.8
CVE-2014-3739
Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web…
Zenoss
No fix yet
MEDIUM 6.8
CVE-2010-0713
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authe…
Zenoss
after 2.4.5
MEDIUM 6.5
CVE-2010-0712
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticat…
Zenoss
after 2.4.5