Записи Centreon
127 опубликованных записей вендора centreon.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 1,6 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 25,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')51
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')31
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-425 Direct Request ('Forced Browsing')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
127 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2022-41142Эксплойта нет | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Высокая8,8 | — | 85,0 % | 26 янв. 2023 г. |
58В плане | CVE-2022-42425Эксплойта нет | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Высокая8,8 | — | 76,1 % | 29 мар. 2023 г. |
58В плане | CVE-2022-42427Эксплойта нет | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Высокая8,8 | — | 76,1 % | 29 мар. 2023 г. |
58В плане | CVE-2022-42424Эксплойта нет | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Высокая8,8 | — | 76,1 % | 29 мар. 2023 г. |
58В плане | CVE-2022-42429Эксплойта нет | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Высокая8,8 | — | 76,1 % | 29 мар. 2023 г. |
57В плане | CVE-2024-0637Эксплойта нет | Centreon updateDirectory SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая8,8 | — | 72,3 % | 1 апр. 2024 г. |
49В плане | CVE-2024-5725Эксплойта нет | Centreon initCurveList SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая8,8 | — | 47,4 % | 21 авг. 2024 г. |
48В плане | CVE-2024-23115Эксплойта нет | Centreon updateGroups SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая7,2 | — | 67,5 % | 1 апр. 2024 г. |
47В плане | CVE-2024-5723Эксплойта нет | Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая8,8 | — | 40,7 % | 21 авг. 2024 г. |
45В плане | CVE-2019-13024Proof of concept | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands bcentreon · centreon · CWE-77 | Высокая8,8 | — | 32,2 % | 1 июл. 2019 г. |
45В плане | CVE-2024-32501Эксплойта нет | A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,centreon · centreon web · CWE-89 | Критическая9,8 | — | 19,2 % | 23 авг. 2024 г. |
44В плане | CVE-2024-23117Эксплойта нет | Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая7,2 | — | 53,4 % | 1 апр. 2024 г. |
44В плане | CVE-2024-23118Эксплойта нет | Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая7,2 | — | 53,4 % | 1 апр. 2024 г. |
44В плане | CVE-2024-23116Эксплойта нет | Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Высокая7,2 | — | 53,4 % | 1 апр. 2024 г. |
43В плане | CVE-2021-37557Эксплойта нет | A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pricentreon · centreon · CWE-89 | Высокая8,8 | — | 27,4 % | 3 авг. 2021 г. |
43В плане | CVE-2021-37556Эксплойта нет | A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pricentreon · centreon · CWE-89 | Высокая8,8 | — | 27,4 % | 3 авг. 2021 г. |
43В плане | CVE-2019-15298Эксплойта нет | A problem was found in Centreon Web through 19.04.3.centreon · centreon web · CWE-78 | Высокая8,8 | — | 26,6 % | 27 нояб. 2019 г. |
43В плане | CVE-2025-15029Эксплойта нет | An unauthenticated user is able to introduce SQL Injection using the Awie export modulecentreon · awie · CWE-89 | Критическая9,8 | — | 12,7 % | 5 янв. 2026 г. |
40В плане | CVE-2018-11587Эксплойта нет | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraphcentreon · centreon · CWE-94 | Критическая9,8 | — | 4,2 % | 25 июн. 2018 г. |
40В плане | CVE-2018-21025Эксплойта нет | In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced centreon · centreon vm · CWE-269 | Критическая9,8 | — | 2,8 % | 8 окт. 2019 г. |
40В плане | CVE-2018-21024Эксплойта нет | licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.centreon · centreon · CWE-434 | Критическая9,8 | — | 2,2 % | 8 окт. 2019 г. |
40В плане | CVE-2018-11589Эксплойта нет | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.pcentreon · centreon · CWE-89 | Критическая9,8 | — | 2,1 % | 25 июн. 2018 г. |
40В плане | CVE-2021-37558Эксплойта нет | A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackercentreon · centreon · CWE-89 | Критическая9,8 | — | 2,1 % | 3 авг. 2021 г. |
40В плане | CVE-2019-17647Эксплойта нет | An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.centreon · centreon · CWE-89 | Критическая9,8 | — | 1,8 % | 5 мар. 2020 г. |
40В плане | CVE-2018-19281Эксплойта нет | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.centreon · centreon · CWE-89 | Критическая9,8 | — | 1,8 % | 14 нояб. 2018 г. |
- CVE-2022-4114261На этой неделе
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
ВысокаяCVSS 8,8Эксплойта нетEPSS 85 %centreon · centreon26 янв. 2023 г.
- CVE-2022-4242558В плане
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %centreon · centreon29 мар. 2023 г.
- CVE-2022-4242758В плане
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %centreon · centreon29 мар. 2023 г.
- CVE-2022-4242458В плане
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %centreon · centreon29 мар. 2023 г.
- CVE-2022-4242958В плане
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
ВысокаяCVSS 8,8Эксплойта нетEPSS 76 %centreon · centreon29 мар. 2023 г.
- CVE-2024-063757В плане
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 72 %centreon · centreon web1 апр. 2024 г.
- CVE-2024-572549В плане
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 47 %centreon · centreon web21 авг. 2024 г.
- CVE-2024-2311548В плане
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 67 %centreon · centreon web1 апр. 2024 г.
- CVE-2024-572347В плане
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 41 %centreon · centreon web21 авг. 2024 г.
- CVE-2019-1302445В плане
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands b
ВысокаяCVSS 8,8Proof of conceptEPSS 32 %centreon · centreon1 июл. 2019 г.
- CVE-2024-3250145В плане
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,
КритическаяCVSS 9,8Эксплойта нетEPSS 19 %centreon · centreon web23 авг. 2024 г.
- CVE-2024-2311744В плане
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 53 %centreon · centreon web1 апр. 2024 г.
- CVE-2024-2311844В плане
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 53 %centreon · centreon web1 апр. 2024 г.
- CVE-2024-2311644В плане
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 53 %centreon · centreon web1 апр. 2024 г.
- CVE-2021-3755743В плане
A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pri
ВысокаяCVSS 8,8Эксплойта нетEPSS 27 %centreon · centreon3 авг. 2021 г.
- CVE-2021-3755643В плане
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pri
ВысокаяCVSS 8,8Эксплойта нетEPSS 27 %centreon · centreon3 авг. 2021 г.
- CVE-2019-1529843В плане
A problem was found in Centreon Web through 19.04.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 27 %centreon · centreon web27 нояб. 2019 г.
- CVE-2025-1502943В плане
An unauthenticated user is able to introduce SQL Injection using the Awie export module
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %centreon · awie5 янв. 2026 г.
- CVE-2018-1158740В плане
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %centreon · centreon25 июн. 2018 г.
- CVE-2018-2102540В плане
In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %centreon · centreon vm8 окт. 2019 г.
- CVE-2018-2102440В плане
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %centreon · centreon8 окт. 2019 г.
- CVE-2018-1158940В плане
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.p
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %centreon · centreon25 июн. 2018 г.
- CVE-2021-3755840В плане
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %centreon · centreon3 авг. 2021 г.
- CVE-2019-1764740В плане
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %centreon · centreon5 мар. 2020 г.
- CVE-2018-1928140В плане
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %centreon · centreon14 нояб. 2018 г.