Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cacti MEDIUM 6.5
CVE-2026-40084

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report fo…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Cacti MEDIUM 6.5
CVE-2026-40941

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allow…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Cacti HIGH 7.2
CVE-2026-40083

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+impl…

Fix: 1.2.31+
Fix from $1,950 2026-06-25
Cacti MEDIUM 6.1
CVE-2026-40080

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring che…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Cacti MEDIUM 5.4
CVE-2026-40082

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leadi…

Fix: 1.2.31+
Fix from $1,600 2026-06-25
Cacti CRITICAL 9.8
CVE-2026-40079

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sani…

Fix: 1.2.31+
Fix from $2,300 2026-06-25
Cacti HIGH 8.8
CVE-2026-39951

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph…

Fix: 1.2.31+
Fix from $1,950 2026-06-25
Cacti CRITICAL 9.8
CVE-2026-39938

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtoo…

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39948

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the …

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39955

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FI…

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Cacti MEDIUM 6.1
CVE-2026-39900

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in th…

Fix: 1.2.31+
Fix from $1,600 2026-06-24
Cacti MEDIUM 5.3
CVE-2026-39899

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter…

Fix: 1.2.31+
Fix from $1,600 2026-06-24
Cacti CRITICAL 9.8
CVE-2026-39893

Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into …

Fix: 1.2.31+
Fix from $2,300 2026-06-24
Cacti MEDIUM 6.1
CVE-2026-39897

Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_…

Fix: 1.2.31+
Fix from $1,600 2026-06-24
Cacti HIGH 8.8
CVE-2025-66399EPSS 11%

Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configurati…

Fix: 1.2.29+
Fix from $1,950 2025-12-02
Cacti HIGH 8.8
CVE-2005-10004

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbit…

Fix: 0.8.6d+
Fix from $1,950 2025-08-30
Cacti CRITICAL 9.8
CVE-2025-26520

Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists be…

Fix: 1.2.29+
Fix from $2,300 2025-02-12
Cacti HIGH 8.8
CVE-2025-24367EPSS 54%

Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functiona…

Fix: 1.2.29+
Fix from $1,950 2025-01-27
Cacti HIGH 7.5
CVE-2025-24368

Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked an…

Fix: 1.2.29+
Fix from $1,950 2025-01-27
Cacti HIGH 7.2
CVE-2025-22604EPSS 5%

Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject ma…

Fix: 1.2.29+
Fix from $1,950 2025-01-27
Cacti HIGH 8.8
CVE-2024-54145

Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of …

Fix: 1.2.29+
Fix from $1,950 2025-01-27
Cacti HIGH 8.8
CVE-2024-54146EPSS 41%

Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_template…

Fix: 1.2.29+
Fix from $1,950 2025-01-27
Cacti HIGH 8.2
CVE-2024-43364EPSS 34%

Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in lin…

Fix: 1.2.28+
Fix from $1,950 2024-10-07
Cacti HIGH 8.2
CVE-2024-43365EPSS 22%

Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external l…

No fix yet
Fix from $1,950 2024-10-07
Cacti HIGH 7.2
CVE-2024-43363EPSS 36%

Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code a…

Fix: 1.2.28+
Fix from $1,950 2024-10-07
Cacti MEDIUM 5.4
CVE-2024-43362EPSS 35%

Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `…

Fix: 1.2.28+
Fix from $1,600 2024-10-07
Cacti MEDIUM 5.4
CVE-2024-27082

Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site script…

Fix: 1.2.27+
Fix from $1,600 2024-05-14
Cacti HIGH 8.8
CVE-2023-51448EPSS 67%

Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNM…

No fix yet
Fix from $1,950 2023-12-22
Cacti MEDIUM 6.1
CVE-2023-50250

Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in vers…

No fix yet
Fix from $1,600 2023-12-22
Cacti HIGH 8.8
CVE-2023-49085EPSS 85%

Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code t…

Fix: after 1.2.25
Fix from $1,950 2023-12-22