Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.99% | — | Cacti | 10/11/2017 | 17/6/2026 | Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php. | |
| Modificada | Media (4.9) | 1.5% | — | Cacti | 8/11/2017 | 17/6/2026 | Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd. | |
| Modificada | Alta (7.2) | 4.2% | — | Cacti | 8/11/2017 | 17/6/2026 | Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header. | |
| Modificada | Alta (7.2) | 3.2% | — | Cacti | 7/11/2017 | 17/6/2026 | lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php. | |
| Modificada | Media (6.1) | 1.1% | — | Cacti | 11/10/2017 | 17/6/2026 | include/global_session.php in Cacti 1.1.25 has XSS related to (1) the URI or (2) the refresh page. | |
| Modificada | Media (5.4) | 0.79% | — | Cacti | 21/8/2017 | 17/6/2026 | lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user. | |
| Modificada | Media (6.1) | 1.4% | — | Cacti | 18/8/2017 | 17/6/2026 | A cross-site scripting vulnerability exists in Cacti 1.1.17 in the method parameter in spikekill.php. | |
| Modificada | Media (5.4) | 1.4% | — | Cacti | 1/8/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the… | |
| Modificada | Crítica (9.8) | 2.9% | — | Cacti | 1/8/2017 | 17/6/2026 | spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter. | |
| Modificada | Media (5.4) | 2.0% | — | Cacti | 27/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in auth_profile.php in Cacti 1.1.13 allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers. | |
| Modificada | Media (6.1) | 0.89% | — | Cacti | 17/7/2017 | 17/6/2026 | Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php. | |
| Modificada | Alta (8.8) | 1.4% | — | Cacti | 17/7/2017 | 17/6/2026 | SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters. | |
| Modificada | Media (5.4) | 1.3% | — | Cacti | 10/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. | |
| Modificada | Media (5.4) | 0.64% | — | Cacti | 6/7/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php. | |
| Modificada | Alta (8.8) | 2.7% | — | CactiOpensuse LeapOpensuse | 13/4/2016 | 17/6/2026 | auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database. | |
| Modificada | Alta (8.8) | 2.8% | — | Cacti | 12/4/2016 | 17/6/2026 | SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action. | |
| Modificada | Alta (8.8) | 2.3% | — | Cacti | 11/4/2016 | 17/6/2026 | SQL injection vulnerability in the host_new_graphs function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via the cg_g parameter in a save action. | |
| Modificada | Alta (8.8) | 2.3% | — | Cacti | 11/4/2016 | 17/6/2026 | SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group_data parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Cacti | 17/12/2015 | 17/6/2026 | SQL injection vulnerability in include/top_graph_header.php in Cacti 0.8.8f and earlier allows remote attackers to execute arbitrary SQL commands via the rra_id parameter in a properties action to graph.php. | |
| Modificada | Media (6.5) | 1.7% | — | Cacti | 15/12/2015 | 17/6/2026 | SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php in Cacti 0.8.8f and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted serialized data in the selected_graphs_array parameter in a save action. | |
| Modificada | Alta (7.5) | 2.2% | — | Cacti | 11/8/2015 | 17/6/2026 | SQL injection vulnerability in graphs.php in Cacti before 0.8.8e allows remote attackers to execute arbitrary SQL commands via the local_graph_id parameter. | |
| Modificada | Media (4.3) | 1.8% | — | Cacti | 10/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in settings.php in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.2% | — | CactiFedoraproject Fedora | 17/6/2015 | 17/6/2026 | SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php. | |
| Modificada | Alta (7.5) | 3.2% | — | CactiFedoraproject Fedora | 17/6/2015 | 17/6/2026 | SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id. | |
| Modificada | Media (4.3) | 2.1% | — | CactiFedoraproject Fedora | 17/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |