Centreon records
127 published records for vendor centreon.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 1.6%
- Pre-auth RCE
- 7
- With a fix record
- 25.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')51
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')31
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-425 Direct Request ('Forced Browsing')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
127 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2022-41142No exploit | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | High8.8 | — | 85.0% | Jan 26, 2023 |
58Plan | CVE-2022-42425No exploit | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | High8.8 | — | 76.1% | Mar 29, 2023 |
58Plan | CVE-2022-42427No exploit | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | High8.8 | — | 76.1% | Mar 29, 2023 |
58Plan | CVE-2022-42424No exploit | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | High8.8 | — | 76.1% | Mar 29, 2023 |
58Plan | CVE-2022-42429No exploit | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | High8.8 | — | 76.1% | Mar 29, 2023 |
57Plan | CVE-2024-0637No exploit | Centreon updateDirectory SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High8.8 | — | 72.3% | Apr 1, 2024 |
49Plan | CVE-2024-5725No exploit | Centreon initCurveList SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High8.8 | — | 47.4% | Aug 21, 2024 |
48Plan | CVE-2024-23115No exploit | Centreon updateGroups SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High7.2 | — | 67.5% | Apr 1, 2024 |
47Plan | CVE-2024-5723No exploit | Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High8.8 | — | 40.7% | Aug 21, 2024 |
45Plan | CVE-2019-13024Proof of concept | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands bcentreon · centreon · CWE-77 | High8.8 | — | 32.2% | Jul 1, 2019 |
45Plan | CVE-2024-32501No exploit | A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,centreon · centreon web · CWE-89 | Critical9.8 | — | 19.2% | Aug 23, 2024 |
44Plan | CVE-2024-23117No exploit | Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High7.2 | — | 53.4% | Apr 1, 2024 |
44Plan | CVE-2024-23118No exploit | Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High7.2 | — | 53.4% | Apr 1, 2024 |
44Plan | CVE-2024-23116No exploit | Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | High7.2 | — | 53.4% | Apr 1, 2024 |
43Plan | CVE-2021-37557No exploit | A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pricentreon · centreon · CWE-89 | High8.8 | — | 27.4% | Aug 3, 2021 |
43Plan | CVE-2021-37556No exploit | A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pricentreon · centreon · CWE-89 | High8.8 | — | 27.4% | Aug 3, 2021 |
43Plan | CVE-2019-15298No exploit | A problem was found in Centreon Web through 19.04.3.centreon · centreon web · CWE-78 | High8.8 | — | 26.6% | Nov 27, 2019 |
43Plan | CVE-2025-15029No exploit | An unauthenticated user is able to introduce SQL Injection using the Awie export modulecentreon · awie · CWE-89 | Critical9.8 | — | 12.7% | Jan 5, 2026 |
40Plan | CVE-2018-11587No exploit | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraphcentreon · centreon · CWE-94 | Critical9.8 | — | 4.2% | Jun 25, 2018 |
40Plan | CVE-2018-21025No exploit | In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced centreon · centreon vm · CWE-269 | Critical9.8 | — | 2.8% | Oct 8, 2019 |
40Plan | CVE-2018-21024No exploit | licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.centreon · centreon · CWE-434 | Critical9.8 | — | 2.2% | Oct 8, 2019 |
40Plan | CVE-2018-11589No exploit | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.pcentreon · centreon · CWE-89 | Critical9.8 | — | 2.1% | Jun 25, 2018 |
40Plan | CVE-2021-37558No exploit | A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackercentreon · centreon · CWE-89 | Critical9.8 | — | 2.1% | Aug 3, 2021 |
40Plan | CVE-2019-17647No exploit | An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.centreon · centreon · CWE-89 | Critical9.8 | — | 1.8% | Mar 5, 2020 |
40Plan | CVE-2018-19281No exploit | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.centreon · centreon · CWE-89 | Critical9.8 | — | 1.8% | Nov 14, 2018 |
- CVE-2022-4114261This week
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
HighCVSS 8.8No exploitEPSS 85%centreon · centreonJan 26, 2023
- CVE-2022-4242558Plan
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
HighCVSS 8.8No exploitEPSS 76%centreon · centreonMar 29, 2023
- CVE-2022-4242758Plan
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
HighCVSS 8.8No exploitEPSS 76%centreon · centreonMar 29, 2023
- CVE-2022-4242458Plan
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
HighCVSS 8.8No exploitEPSS 76%centreon · centreonMar 29, 2023
- CVE-2022-4242958Plan
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
HighCVSS 8.8No exploitEPSS 76%centreon · centreonMar 29, 2023
- CVE-2024-063757Plan
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 72%centreon · centreon webApr 1, 2024
- CVE-2024-572549Plan
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 47%centreon · centreon webAug 21, 2024
- CVE-2024-2311548Plan
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 67%centreon · centreon webApr 1, 2024
- CVE-2024-572347Plan
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 41%centreon · centreon webAug 21, 2024
- CVE-2019-1302445Plan
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands b
HighCVSS 8.8Proof of conceptEPSS 32%centreon · centreonJul 1, 2019
- CVE-2024-3250145Plan
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,
CriticalCVSS 9.8No exploitEPSS 19%centreon · centreon webAug 23, 2024
- CVE-2024-2311744Plan
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 53%centreon · centreon webApr 1, 2024
- CVE-2024-2311844Plan
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 53%centreon · centreon webApr 1, 2024
- CVE-2024-2311644Plan
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability
HighCVSS 7.2No exploitEPSS 53%centreon · centreon webApr 1, 2024
- CVE-2021-3755743Plan
A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pri
HighCVSS 8.8No exploitEPSS 27%centreon · centreonAug 3, 2021
- CVE-2021-3755643Plan
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pri
HighCVSS 8.8No exploitEPSS 27%centreon · centreonAug 3, 2021
- CVE-2019-1529843Plan
A problem was found in Centreon Web through 19.04.3.
HighCVSS 8.8No exploitEPSS 27%centreon · centreon webNov 27, 2019
- CVE-2025-1502943Plan
An unauthenticated user is able to introduce SQL Injection using the Awie export module
CriticalCVSS 9.8No exploitEPSS 13%centreon · awieJan 5, 2026
- CVE-2018-1158740Plan
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph
CriticalCVSS 9.8No exploitEPSS 4%centreon · centreonJun 25, 2018
- CVE-2018-2102540Plan
In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced
CriticalCVSS 9.8No exploitEPSS 3%centreon · centreon vmOct 8, 2019
- CVE-2018-2102440Plan
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
CriticalCVSS 9.8No exploitEPSS 2%centreon · centreonOct 8, 2019
- CVE-2018-1158940Plan
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.p
CriticalCVSS 9.8No exploitEPSS 2%centreon · centreonJun 25, 2018
- CVE-2021-3755840Plan
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attacker
CriticalCVSS 9.8No exploitEPSS 2%centreon · centreonAug 3, 2021
- CVE-2019-1764740Plan
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.
CriticalCVSS 9.8No exploitEPSS 2%centreon · centreonMar 5, 2020
- CVE-2018-1928140Plan
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
CriticalCVSS 9.8No exploitEPSS 2%centreon · centreonNov 14, 2018