Skip to content
Noroxi

Cacti records

155 published records for vendor cacti.

All records

155 records
  • Unauthenticated Command Injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    cacti · cactiDec 5, 2022

  • CVE-2024-29895
    70This week

    Cacti command injection in cmd_realtime.php

    CriticalCVSS 10.0Proof of conceptEPSS 98%

    cacti · cactiMay 14, 2024

  • CVE-2023-39361
    66This week

    Unauthenticated SQL Injection in graph_view.php in Cacti

    CriticalCVSS 9.8Proof of conceptEPSS 89%

    cacti · cactiSep 5, 2023

  • Cacti SQL Injection vulnerability

    HighCVSS 8.8WeaponizedEPSS 74%

    cacti · cactiDec 22, 2023

  • graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest

    HighCVSS 8.8Proof of conceptEPSS 74%

    cacti · cactiFeb 21, 2020

  • SQL Injection vulnerability when managing SNMP Notification Receivers

    HighCVSS 8.8No exploitEPSS 67%

    cacti · cactiDec 22, 2023

  • A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.

    HighCVSS 7.2WeaponizedEPSS 86%

    cacti · cactiJun 17, 2020

  • Cacti RCE vulnerability when importing packages

    HighCVSS 7.2WeaponizedEPSS 86%

    cacti · cactiMay 14, 2024

  • Authenticated command injection in SNMP options of a Device

    HighCVSS 7.2Proof of conceptEPSS 85%

    cacti · cactiSep 5, 2023

  • Local File Inclusion (RCE) in Cacti

    HighCVSS 8.8WeaponizedEPSS 64%

    cacti · cactiDec 21, 2023

  • Cacti allows Arbitrary File Creation leading to RCE

    HighCVSS 8.7WeaponizedEPSS 54%

    cacti · cactiJan 27, 2025

  • Cacti has a SQL Injection vulnerability when view host template

    HighCVSS 8.8No exploitEPSS 41%

    cacti · cactiJan 27, 2025

  • Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_a

    HighCVSS 8.8No exploitEPSS 37%

    cacti · cactiJan 20, 2020

  • Stored Cross-site Scripting (XSS) when creating external links in Cacti

    HighCVSS 8.2No exploitEPSS 38%

    cacti · cactiOct 7, 2024

  • SQL Injection vulnerability in automation_get_new_graphs_sql

    HighCVSS 8.8No exploitEPSS 26%

    cacti · cactiMay 14, 2024

  • Stored Cross-site Scripting (XSS) when creating external links in Cacti

    HighCVSS 8.2No exploitEPSS 25%

    cacti · cactiOct 7, 2024

  • Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

    CriticalCVSS 9.8No exploitEPSS 3%

    cacti · cactiMar 3, 2022

  • spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end pa

    CriticalCVSS 9.8No exploitEPSS 3%

    cacti · cactiAug 1, 2017

  • Remote code execution via Log Poisoning in Cacti

    HighCVSS 7.2Proof of conceptEPSS 36%

    cacti · cactiOct 7, 2024

  • CVE-2009-4112
    39Monitor

    Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux -

    CriticalCVSS 9.0Proof of conceptEPSS 11%

    cacti · cactiNov 30, 2009

  • Cacti: Unauthenticated RCE on Graph Image

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    cacti · cactiJun 24, 2026

  • Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php

    CriticalCVSS 9.8No exploitEPSS 1%

    cacti · cactiJun 24, 2026

  • Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php

    CriticalCVSS 9.8No exploitEPSS 1%

    cacti · cactiJun 24, 2026

  • Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter.

    CriticalCVSS 9.8No exploitEPSS 0%

    cacti · cactiFeb 12, 2025

  • Cacti has SQL Injection via rfilter parameter in RLIKE clauses

    CriticalCVSS 9.3No exploitEPSS 1%

    cacti · cactiJun 24, 2026