Vulnerability index

Browse CVEs

89 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Librenms CRITICAL 9.1
CVE-2024-51092EPSS 7%

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), Settings…

Fix: 24.10.0+
Fix from $2,300 2026-05-08
Librenms HIGH 7.2
CVE-2026-6204EPSS 8%

LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the N…

Fix: 26.3.0+
Fix from $1,950 2026-04-13
Librenms MEDIUM 5.4
CVE-2026-27016

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 24.10.0 through 26.1.1 are vulnerable to Stored XSS via the un…

Fix: 26.2.0+
Fix from $1,600 2026-02-20
Librenms CRITICAL 9.1
CVE-2026-26988EPSS 7%

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in th…

Fix: 26.2.0+
Fix from $2,300 2026-02-20
Librenms HIGH 8.8
CVE-2026-26990

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below have a Time-Based Blind SQL Injection vulner…

Fix: 26.2.0+
Fix from $1,950 2026-02-20
Librenms MEDIUM 6.1
CVE-2026-26987

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below are vulnerable to Reflected XSS attacks via…

Fix: 26.2.0+
Fix from $1,600 2026-02-20
Librenms MEDIUM 6.5
CVE-2020-36947

LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract data…

No fix yet
Fix from $1,600 2026-01-27
Librenms MEDIUM 5.4
CVE-2025-68614

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cr…

Fix: 25.12.0+
Fix from $1,600 2025-12-23
Librenms MEDIUM 5.5
CVE-2025-65093

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerabi…

Fix: 25.11.0+
Fix from $1,600 2025-11-18
Librenms MEDIUM 6.1
CVE-2025-65013

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulner…

Fix: 25.11.0+
Fix from $1,600 2025-11-18
Librenms MEDIUM 6.1
CVE-2025-62365

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `l…

Fix: 25.7.0+
Fix from $1,600 2025-10-13
Librenms MEDIUM 5.4
CVE-2025-55296EPSS 12%

librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0…

Fix: 25.8.0+
Fix from $1,600 2025-08-18
Librenms HIGH 7.5
CVE-2025-54138

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating sys…

Fix: 25.7.0+
Fix from $1,950 2025-07-22
Librenms MEDIUM 6.1
CVE-2025-47931

LibreNMS is PHP/MySQL/SNMP based network monitoring software. LibreNMS v25.4.0 and prior suffers from a Stored Cross-Site Scripting (XSS) Vulnerabili…

Fix: 25.5.0+
Fix from $1,600 2025-05-17
Librenms MEDIUM 6.1
CVE-2025-23201

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to Cross-site Scripting (XSS) on the parameters:`…

Fix: 24.11.0+
Fix from $1,600 2025-01-16
Librenms MEDIUM 5.4
CVE-2025-23198

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVIC…

Fix: 24.11.0+
Fix from $1,600 2025-01-16
Librenms MEDIUM 5.4
CVE-2025-23199

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `/ajax_form.php…

Fix: 24.11.0+
Fix from $1,600 2025-01-16
Librenms MEDIUM 5.4
CVE-2025-23200EPSS 31%

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameter: `ajax_form.php`…

Fix: 24.11.0+
Fix from $1,600 2025-01-16
Librenms MEDIUM 5.4
CVE-2024-56144

librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on the parameters (Replace $DEVIC…

Fix: 24.12.0+
Fix from $1,600 2025-01-16
Librenms MEDIUM 5.4
CVE-2024-53457EPSS 42%

A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrar…

Fix: after 24.10.0
Fix from $1,600 2024-12-05
Librenms MEDIUM 5.4
CVE-2024-52526

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab o…

Patch available
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-51494

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" …

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-51495

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview …

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-51496

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" para…

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-51497

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab…

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-49759

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Acc…

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-49764

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug I…

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-50350

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" …

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-50351

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" par…

Fix: 24.10.0+
Fix from $1,600 2024-11-15
Librenms MEDIUM 5.4
CVE-2024-50352EPSS 37%

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" secti…

Fix: 24.10.0+
Fix from $1,600 2024-11-15