Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lpar2rrd HIGH 8.8
CVE-2025-54769

An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing…

Fix: after 8.04
Fix from $1,950 2025-07-29
Lpar2rrd MEDIUM 6.5
CVE-2025-54767EPSS 6%

An authenticated, read-only user can kill any processes running on the Xormon Original virtual appliance as the lpar2rrd user.

Fix: after 8.04
Fix from $1,600 2025-07-29
Xormon MEDIUM 5.3
CVE-2025-54766EPSS 7%

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application use…

Fix: after 1.8.0
Fix from $1,600 2025-07-29
Lpar2rrd MEDIUM 5.3
CVE-2025-54768

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application use…

Fix: after 8.04
Fix from $1,600 2025-07-29
Xormon MEDIUM 5.3
CVE-2025-54765EPSS 7%

An API endpoint that should be limited to web application administrators is hidden from, but accessible by, lower-level read only web application use…

Fix: after 1.8.0
Fix from $1,600 2025-07-29
Lpar2rrd CRITICAL 9.8
CVE-2021-42371

lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.

Fix: 7.30+
Fix from $2,300 2021-11-08
Lpar2rrd HIGH 8.8
CVE-2021-42372EPSS 6%

A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute…

Fix: 7.30+
Fix from $1,950 2021-11-08
Lpar2rrd HIGH 7.5
CVE-2021-42370

A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input …

Fix: 7.30+
Fix from $1,950 2021-11-08
Lpar2rrd CRITICAL 9.8
CVE-2020-24032EPSS 5%

tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.

Mitigation only
Fix from $2,300 2020-08-18
Lpar2rrd CRITICAL 9.8
CVE-2014-4981EPSS 6%

LPAR2RRD in 3.5 and earlier allows remote attackers to execute arbitrary commands due to insufficient input sanitization of the web GUI parameters.

Fix: after 3.50
Fix from $2,300 2020-02-17
Lpar2rrd CRITICAL 9.8
CVE-2014-4982

LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.

Fix: after 4.53
Fix from $2,300 2020-01-10