Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.99%—Cacti10/11/201717/6/2026
Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
ModificadaMedia (4.9)1.5%—Cacti8/11/201717/6/2026
Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd.
ModificadaAlta (7.2)4.2%—Cacti8/11/201717/6/2026
Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header.
ModificadaAlta (7.2)3.2%—Cacti7/11/201717/6/2026
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php.
ModificadaMedia (6.1)1.1%—Cacti11/10/201717/6/2026
include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page.
ModificadaMedia (5.4)0.79%—Cacti21/8/201717/6/2026
lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.
ModificadaMedia (6.1)1.4%—Cacti18/8/201717/6/2026
A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php.
ModificadaMedia (5.4)1.4%—Cacti1/8/201717/6/2026
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the…
ModificadaCrítica (9.8)2.9%—Cacti1/8/201717/6/2026
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
ModificadaMedia (5.4)2.0%—Cacti27/7/201717/6/2026
Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
ModificadaMedia (6.1)0.89%—Cacti17/7/201717/6/2026
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.
ModificadaAlta (8.8)1.4%—Cacti17/7/201717/6/2026
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
ModificadaMedia (5.4)1.3%—Cacti10/7/201717/6/2026
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable.
ModificadaMedia (5.4)0.64%—Cacti6/7/201717/6/2026
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.
ModificadaAlta (8.8)2.7%—CactiOpensuse LeapOpensuse13/4/201617/6/2026
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
ModificadaAlta (8.8)2.8%—Cacti12/4/201617/6/2026
SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.
ModificadaAlta (8.8)2.3%—Cacti11/4/201617/6/2026
SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action.
ModificadaAlta (8.8)2.3%—Cacti11/4/201617/6/2026
SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter.
ModificadaAlta (7.5)2.3%—Cacti17/12/201517/6/2026
SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php.
ModificadaMedia (6.5)1.7%—Cacti15/12/201517/6/2026
SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action.
ModificadaAlta (7.5)2.2%—Cacti11/8/201517/6/2026
SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter.
ModificadaMedia (4.3)1.8%—Cacti10/7/201517/6/2026
Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.2%—CactiFedoraproject Fedora17/6/201517/6/2026
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
ModificadaAlta (7.5)3.2%—CactiFedoraproject Fedora17/6/201517/6/2026
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
ModificadaMedia (4.3)2.1%—CactiFedoraproject Fedora17/6/201517/6/2026
Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades