Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 3.1% | — | Cacti | 27/1/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply going to Logs tab and selecting the name… | |
| Modificada | Alta (8.2) | 25% | — | Cacti | 7/10/2024 | 17/6/2026 | Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the said consolenewsection parameter is stored in the database and reflected back to user in `index.php`, finally leading to stored XSS.… | |
| Modificada | Alta (8.2) | 38% | — | Cacti | 7/10/2024 | 17/6/2026 | Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, the said title parameter is stored in the database and reflected back to user in index.php, finally leading to stored XSS. Users with the privilege to… | |
| Modificada | Alta (7.2) | 36% | 💥 PoC | Cacti | 7/10/2024 | 17/6/2026 | Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as… | |
| Modificada | Media (5.4) | 39% | — | Cacti | 7/10/2024 | 17/6/2026 | Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, the said fileurl is placed in some html code which is passed to the `print` function in `link.php` and `index.php`, finally leading to stored XSS.… | |
| Modificada | Crítica (9.1) | 1.1% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In… | |
| Modificada | Alta (8.8) | 1.8% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_nodes()` function from `lib/api_automation.php` , finally resulting in… | |
| Modificada | Alta (7.2) | 2.7% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the `api_plugin_hook()` function in… | |
| Modificada | Alta (8) | 13% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement in `draw_nontemplated_fields_graph_item()` function from… | |
| Modificada | Alta (8.8) | 26% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code… | |
| Modificada | Media (5.4) | 15% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the HTML statement in `form_confirm()` function from… | |
| Modificada | Media (5.4) | 0.84% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_pane_tree()` function from `lib/html.php` , finally resulting in… | |
| Aplazada | Media (6.1) | 0.59% | — | CactiAI | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained cookies. This issue is fixed in commit… | |
| Aplazada | Crítica (10) | 98% | 💥 Exploit | CactiAIPHPAI | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `On`. In `cmd_realtime.php` line 119, the `$poller_id` used as part of… | |
| Analizada | Media (4.7) | 0.90% | — | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others).… | |
| Analizada | Media (5.4) | 0.92% | — | Cacti | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 are vulnerable to stored cross-site scripting, a type of cross-site scripting where malicious scripts are permanently stored on a target server and served to users who access a particular page. Version 1.2.27… | |
| Modificada | Alta (7.2) | 86% | 💥 Exploit | CactiFedoraproject Fedora | 14/5/2024 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, an arbitrary file write vulnerability, exploitable through the "Package Import" feature, allows authenticated users having the "Import Templates" permission to execute arbitrary PHP code on the web server. The… | |
| Modificada | Alta (8.8) | 67% | — | Cacti | 22/12/2023 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. Version 1.2.25 has a Blind SQL Injection (SQLi) vulnerability within the SNMP Notification Receivers feature in the file `‘managers.php’`. An authenticated attacker with the “Settings/Utilities” permission can send a crafted HTTP GET request to… | |
| Analizada | Media (6.1) | 1.3% | — | Cacti | 22/12/2023 | 17/6/2026 | Cacti is an open source operational monitoring and fault management framework. A reflection cross-site scripting vulnerability was discovered in version 1.2.25. Attackers can exploit this vulnerability to perform actions on behalf of other users. The vulnerability is found in `templates_import.php.` When uploading an… | |
| Modificada | Media (4.8) | 1.3% | — | Cacti | 22/12/2023 | 17/6/2026 | Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious data source path in `data_debug.php`. To… | |
| Modificada | Alta (8.8) | 74% | 💥 Exploit | Cacti | 22/12/2023 | 17/6/2026 | Cacti provides an operational monitoring and fault management framework. In versions 1.2.25 and prior, it is possible to execute arbitrary SQL code through the `pollers.php` script. An authorized user may be able to execute arbitrary SQL code. The vulnerable component is the `pollers.php`. Impact of the vulnerability… | |
| Modificada | Media (5.4) | 1.5% | — | Cacti | 22/12/2023 | 17/6/2026 | Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). A vulnerability in versions prior to 1.2.27 bypasses an earlier fix for CVE-2023-39360, therefore leading to a DOM XSS attack. Exploitation of the vulnerability is possible for an authorized user.… | |
| Modificada | Alta (8.8) | 64% | 💥 Exploit | Cacti | 21/12/2023 | 17/6/2026 | Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for… | |
| Modificada | Media (6.5) | 1.4% | — | Cacti | 27/10/2023 | 17/6/2026 | SQL Injection vulnerability in Cacti v1.2.25 allows a remote attacker to obtain sensitive information via the form_actions() function in the managers.php function. | |
| Analizada | Media (4.8) | 0.78% | — | CactiFedoraproject Fedora | 6/9/2023 | 17/6/2026 | Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute… |