Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.55% | — | CactiAI | 5/8/2026 | 26/8/2026 | Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letters, digits, underscore, parentheses, and dot (intended to support expressions like COUNT(id) and table.column), a payload such as passes through completely unmodified. | |
| Analizada | Alta (7.1) | 0.27% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue has been fixed in version 1.2.31. | |
| Analizada | Media (6.5) | 0.49% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. This vulnerability occurs in two stages. In the first stage (stored injection), lib/html_reports.php at line 283 stores… | |
| Analizada | Alta (7.2) | 0.50% | — | Cacti | 25/6/2026 | 30/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assigns $selected_items by calling cacti_unserialize(stripslashes(gnrv('selected_graphs_array'))). The… | |
| Analizada | Media (5.4) | 0.32% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. session_regenerate_id() is NOT called after successful login. The login flow at auth_login.php:203-207 directly sets $_SESSION[SESS_USER_ID]… | |
| Analizada | Media (6.1) | 0.26% | — | Cacti | 25/6/2026 | 29/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Redirect through a substring check rather than a host check at str_contains($referer, CACTI_PATH_URL). When the user's login_opts == '1' (redirect to referer after login), the function used… | |
| Analizada | Alta (8.6) | 1.7% | — | Cacti | 25/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The escape_command() function at lib/rrd.php is a no-op: it returns $command unchanged. The command line built by… | |
| Analizada | Alta (8.8) | 0.40% | — | Cacti | 25/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injection vulnerability through graph_name_regexp in the Reports feature. This issue has been fixed in version 1.2.31. | |
| Analizada | Crítica (9.8) | 0.58% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php. This issue has been fixed in version 1.2.31. | |
| Analizada | Crítica (9.3) | 0.85% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request parameter is retrieved via the raw accessor grv() (rather than gfrv() with FILTER_VALIDATE_IS_REGEX validation) and concatenated directly into RLIKE SQL clauses in lib/html_graph.php and… | |
| Analizada | Crítica (9.8) | 0.69% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI through graph_theme and rrdtool IPC serialization hardening. This issue has been resolved in version 1.2.31. | |
| Analizada | Media (5.3) | 0.26% | — | Cacti | 24/6/2026 | 25/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflected XSS via tab parameter in the auth_profile.php JavaScript context. This issue has been fixed in version 1.2.31. | |
| Analizada | Media (6.9) | 0.39% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This issue has been fixed in version 1.2.31. | |
| Analizada | Media (5.3) | 0.26% | — | Cacti | 24/6/2026 | 25/6/2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vulnerability in the html_auth_footer. This issue has been fixed in version 1.2.31. | |
| Analizada | Baja (2.5) | 0.14% | — | Cacti | 24/6/2026 | 25/6/2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric values. The rrdtool_function_update() function checks metric values with is_numeric() and concatenates them into the RRDtool… | |
| Analizada | Crítica (9.8) | 0.67% | — | Cacti | 24/6/2026 | 26/6/2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request variable was concatenated into a RLIKE SQL clause without sanitization. The endpoint does not require authentication (graph viewing supports guest access via the configured guest user), so the SQLi was… | |
| Aplazada | Media (5.4) | 0.22% | — | CactiAI | 29/1/2026 | 17/6/2026 | A HTML injection vulnerability exists in the file upload functionality of Cacti <= 1.2.29. When a file with an invalid format is uploaded, the application reflects the submitted filename back into an error popup without proper sanitization. As a result, attackers can inject arbitrary HTML elements (e.g., <h1>, <b>,… | |
| Analizada | Alta (7.4) | 11% | — | Cacti | 2/12/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw in the SNMP device configuration functionality. An authenticated Cacti user can supply crafted SNMP community strings containing control characters (including newlines) that are accepted, stored… | |
| Analizada | Alta (8.7) | 2.0% | — | Cacti | 30/8/2025 | 23/9/2026 | Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the… | |
| Analizada | Crítica (9.8) | 0.48% | — | Cacti | 12/2/2025 | 17/6/2026 | Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter. NOTE: this issue exists because of an incomplete fix for CVE-2024-54146. | |
| Modificada | Media (6.9) | 0.51% | — | Cacti | 27/1/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Some of the data stored in automation_tree_rules.php is not thoroughly checked and is used to concatenate the SQL statement in build_rule_item_filter() function from lib/api_automation.php, resulting in SQL injection. This vulnerability is fixed in… | |
| Modificada | Alta (8.7) | 54% | — | Cacti | 27/1/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. An authenticated Cacti user can abuse graph creation and graph template functionality to create arbitrary PHP scripts in the web root of the application, leading to remote code execution on the server. This vulnerability is fixed in 1.2.29. | |
| Modificada | Alta (7.2) | 5.4% | — | Cacti | 27/1/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, authenticated users can inject malformed OIDs in the response. When processed by ss_net_snmp_disk_io() or ss_net_snmp_disk_bytes(), a part of each OID will be used as a key in an array that is used as… | |
| Analizada | Alta (8.8) | 41% | — | Cacti | 27/1/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the template function of host_templates.php using the graph_template parameter. This vulnerability is fixed in 1.2.29. | |
| Modificada | Alta (8.8) | 0.68% | — | Cacti | 27/1/2025 | 17/6/2026 | Cacti is an open source performance and fault management framework. Cacti has a SQL injection vulnerability in the get_discovery_results function of automation_devices.php using the network parameter. This vulnerability is fixed in 1.2.29. |