Vulnerability index

Browse CVEs

15 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Cacti HIGH 8.2
CVE-2024-43365EPSS 22%

Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external l…

No fix yet
Fix from $1,950 2024-10-07
Cacti HIGH 8.8
CVE-2023-51448EPSS 67%

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNM…

No fix yet
Fix from $1,950 2023-12-22
Cacti MEDIUM 6.1
CVE-2023-50250

Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in vers…

No fix yet
Fix from $1,600 2023-12-22
Cacti HIGH 8.8
CVE-2023-49084EPSS 64%

Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL …

No fix yet
Fix from $1,950 2023-12-21
Cacti MEDIUM 6.5
CVE-2023-46490

SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers…

No fix yet
Fix from $1,600 2023-10-27
Cacti MEDIUM 5.3
CVE-2022-48538

In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() a…

No fix yet
Fix from $1,600 2023-08-22
Cacti MEDIUM 6.1
CVE-2022-41444

Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php.

No fix yet
Fix from $1,600 2023-08-22
Cacti MEDIUM 6.1
CVE-2021-26247EPSS 7%

As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" to successfully execute the Ja…

Mitigation only
Fix from $1,600 2022-01-19
Cacti MEDIUM 5.4
CVE-2021-3816

Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix field during the creation of a …

Mitigation only
Fix from $1,600 2022-01-19
Cacti HIGH 8.8
CVE-2020-7237EPSS 37%

Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation…

No fix yet
Fix from $1,950 2020-01-20
Cacti HIGH 8.8
CVE-2020-7058

data_input.php in Cacti 1.2.8 allows remote code execution via a crafted Input String to Data Collection -> Data Input Methods -> Unix -> Ping Host. …

No fix yet
Fix from $1,950 2020-01-15
Cacti HIGH 8.8
CVE-2017-1000031

SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_tem…

No fix yet
Fix from $1,950 2017-07-17
Cacti MEDIUM 6.1
CVE-2017-1000032

Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter …

Mitigation only
Fix from $1,600 2017-07-17
Cacti MEDIUM 5.4
CVE-2017-10970

Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id …

Mitigation only
Fix from $1,600 2017-07-06
Superlinks HIGH 7.5
CVE-2014-4644

SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via …

No fix yet
Fix from $1,950 2014-06-25