Vulnerability index

Browse CVEs

107 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web CRITICAL 9.8
CVE-2026-2750

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affec…

Fix: 24.04.24 / 24.10.20+
Fix from $2,300 2026-02-27
Open Tickets HIGH 8.8
CVE-2026-2749

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on…

Fix: 24.04.7 / 24.10.8+
Fix from $1,950 2026-02-27
Centreon Web CRITICAL 9.8
CVE-2026-2751

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (S…

Fix: 24.04.24. / 24.10.20+
Fix from $2,300 2026-02-27
Awie CRITICAL 9.8
CVE-2025-15026

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functiona…

Fix: 24.04.3 / 24.10.3+
Fix from $2,300 2026-01-05
Awie CRITICAL 9.8
CVE-2025-15029EPSS 11%

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules)…

Fix: 24.04.3 / 24.10.3+
Fix from $2,300 2026-01-05
Centreon Web MEDIUM 5.3
CVE-2025-12519

Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not …

Fix: 24.04.19 / 24.10.15+
Fix from $1,600 2026-01-05
Centreon Web HIGH 7.2
CVE-2025-5965EPSS 26%

In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Speci…

Fix: 24.04.19 / 24.10.15+
Fix from $1,950 2026-01-05
Open Tickets HIGH 7.2
CVE-2025-12514

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notif…

Fix: 23.10.4 / 24.04.5+
Fix from $1,950 2025-12-22
Centreon Web MEDIUM 5.4
CVE-2025-8459

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Monitoring re…

Fix: 23.10.28 / 24.04.18+
Fix from $1,600 2025-10-14
Centreon Web MEDIUM 5.4
CVE-2025-8428

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (HTTP Loader w…

Fix: 23.10.28 / 24.04.18+
Fix from $1,600 2025-10-14
Centreon Web HIGH 7.2
CVE-2025-5946EPSS 14%

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload …

Fix: 23.10.28 / 24.04.18+
Fix from $1,950 2025-10-14
Centreon Web HIGH 8.8
CVE-2025-6791

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralizati…

Fix: 23.10.26 / 24.04.16+
Fix from $1,950 2025-08-22
Centreon Web HIGH 7.2
CVE-2025-4650

User with high privileges is able to introduce a SQLi using the Meta Service indicator page. Caused by an Improper Neutralization of Special Elements…

Fix: 23.10.26 / 24.04.16+
Fix from $1,950 2025-08-22
Centreon Web HIGH 7.2
CVE-2025-4646

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.0…

Fix: 24.04.10 / 24.10.4+
Fix from $1,950 2025-05-13
Centreon Web MEDIUM 5.9
CVE-2025-4648

The content of a SVG file, received as input in Centreon web, was not properly checked. Allows Reflected XSS. A user with elevated privileges can i…

Fix: 22.10.29 / 23.04.27+
Fix from $1,600 2025-05-13
Centreon Web HIGH 7.2
CVE-2025-3872

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form …

Fix: 22.10.28 / 23.04.25+
Fix from $1,950 2025-04-24
Centreon Web HIGH 7.2
CVE-2024-55573

An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A …

Fix: 23.04.24 / 23.10.19+
Fix from $1,950 2025-01-23
Centreon Web HIGH 7.2
CVE-2024-53923

An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with…

Fix: 23.04.24 / 23.10.19+
Fix from $1,950 2025-01-23
Centreon HIGH 7.2
CVE-2024-39842

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes …

Mitigation only
Fix from $1,950 2024-09-23
Centreon MEDIUM 6.7
CVE-2024-39843

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inpu…

Mitigation only
Fix from $1,600 2024-09-23
Centreon Web CRITICAL 9.8
CVE-2024-32501EPSS 19%

A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x …

Fix: 22.10.23 / 23.04.19+
Fix from $2,300 2024-08-23
Centreon Web CRITICAL 9.1
CVE-2024-33852

A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.…

Fix: 22.10.23 / 23.04.19+
Fix from $2,300 2024-08-23
Centreon Web CRITICAL 9.1
CVE-2024-33853

A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.0…

Fix: 22.10.23 / 23.04.19+
Fix from $2,300 2024-08-23
Centreon Web CRITICAL 9.1
CVE-2024-33854

A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before …

Fix: 22.10.23 / 23.04.19+
Fix from $2,300 2024-08-23
Centreon Web HIGH 8.8
CVE-2024-39841

A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.0…

Fix: 22.10.23 / 23.04.19+
Fix from $1,950 2024-08-23
Centreon Web HIGH 8.8
CVE-2024-5723EPSS 41%

Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…

Fix: 22.04.24 / 22.10.22+
Fix from $1,950 2024-08-21
Centreon Web HIGH 8.8
CVE-2024-5725EPSS 47%

Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…

Fix: 22.10.23 / 23.04.19+
Fix from $1,950 2024-08-21
Centreon Web CRITICAL 9.6
CVE-2023-51633

Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af…

Fix: 22.10.15 / 23.04.10+
Fix from $2,300 2024-05-03
Centreon Web HIGH 8.8
CVE-2024-23119

Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Fix: 22.04.19 / 22.10.17+
Fix from $1,950 2024-04-01
Centreon Web HIGH 7.2
CVE-2024-23117EPSS 53%

Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Fix: 22.04.19 / 22.10.17+
Fix from $1,950 2024-04-01