Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.90% | — | Icinga 2AI | 18/9/2026 | 24/9/2026 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an objects/create/* permission can inject Icinga 2 DSL configuration, escape the… | |
| Pendiente de análisis | Alta (8.6) | 0.94% | — | Icinga 2AI | 18/9/2026 | 24/9/2026 | Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticated network clients through the Icinga 2 service on TCP port 5665, allowing a… | |
| Pendiente de análisis | Crítica (9.8) | 0.67% | — | Icinga 2AI | 18/9/2026 | 24/9/2026 | Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the node certificate and trusted CA… | |
| Pendiente de análisis | Alta (8.3) | 0.42% | — | Linuxfabrik Monitoring-pluginsAIIcingaAINagiosAI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect… | |
| Aplazada | Alta (7.6) | 0.45% | — | Icinga WEBAI | 8/5/2026 | 17/6/2026 | ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance… | |
| Aplazada | Media (4.8) | 0.30% | — | Icinga WEBAI | 1/2/2026 | 17/6/2026 | Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through the icinga.min.js file. Attackers can exploit the EventListener.handleEvent method to execute arbitrary scripts, potentially leading to session hijacking and non-persistent… | |
| Analizada | Media (6.8) | 0.10% | — | Icinga Powershell Framework | 29/1/2026 | 17/6/2026 | The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of… | |
| Analizada | Media (6.8) | 0.08% | — | Icinga | 29/1/2026 | 17/6/2026 | Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced… | |
| Analizada | Media (4) | 0.21% | — | Icinga | 16/10/2025 | 17/6/2026 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the… | |
| Analizada | Alta (7.1) | 0.53% | — | Icinga | 16/10/2025 | 17/6/2026 | Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a filter expression to… | |
| Analizada | Alta (7.1) | 0.40% | — | Icinga | 16/10/2025 | 17/6/2026 | Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden… | |
| Analizada | Media (6.5) | 0.36% | — | Icinga DB WEB | 16/10/2025 | 17/6/2026 | Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions… | |
| Analizada | Baja (2.4) | 0.26% | — | Icinga DB WEB | 16/7/2025 | 17/6/2026 | Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be revealed nor does… | |
| Analizada | Crítica (9.3) | 0.44% | — | Icinga | 27/5/2025 | 17/6/2026 | Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an… | |
| Analizada | Media (6.1) | 0.26% | — | Icinga WEB 2 | 26/3/2025 | 17/6/2026 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to… | |
| Analizada | Baja (1.1) | 0.25% | — | Icinga WEB 2 | 26/3/2025 | 17/6/2026 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on behalf of that user.… | |
| Aplazada | Alta (7.6) | 0.32% | — | Icinga ReportingAIIcinga WEB 2AI | 26/3/2025 | 17/6/2026 | Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the… | |
| Analizada | Media (6.1) | 0.33% | — | Icinga WEB 2 | 26/3/2025 | 17/6/2026 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has… | |
| Analizada | Media (6.1) | 0.60% | — | Icinga WEB 2 | 26/3/2025 | 17/6/2026 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has… | |
| Aplazada | Media (5.5) | 0.40% | — | Icinga DirectorAI | 26/3/2025 | 17/6/2026 | Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the Director is required (plus api access with… | |
| Analizada | Crítica (9.8) | 2.9% | — | IcingaDebian Linux | 12/11/2024 | 17/6/2026 | Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as… | |
| Aplazada | Baja (3.9) | 0.18% | — | Icinga-php-libraryAI | 5/8/2024 | 17/6/2026 | ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded. Version 0.10.1 includes a fix… | |
| Modificada | Alta (8.8) | 0.26% | — | Icingaweb2-module-incubator | 9/2/2024 | 17/6/2026 | icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This is done by automatically adding an… | |
| Modificada | Alta (8.3) | 0.40% | — | Icinga | 9/2/2024 | 17/6/2026 | Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the monitoring environment managed by… | |
| Modificada | Alta (8.8) | 0.26% | — | Icinga WEB Jira Integration | 5/7/2023 | 17/6/2026 | icingaweb2-module-jira provides integration with Atlassian Jira. Starting in version 1.3.0 and prior to version 1.3.2, template and field configuration forms perform the deletion action before user input is validated, including the cross site request forgery token. This issue is fixed in version 1.3.2. There are no… |