icinga records
49 published records for vendor icinga.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 4.1%
- Pre-auth RCE
- 2
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-295 Improper Certificate Validation3
- CWE-732 Incorrect Permission Assignment for Critical Resource3
The weakness classes this vendor ships most often: where to look.
CWEAll records
49 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
57Plan | CVE-2022-24716Weaponized | Path traversal in Icinga Web 2icinga · icinga web 2 · CWE-22 | High7.5 | — | 89.4% | Mar 8, 2022 |
50Plan | CVE-2012-6096Weaponized | Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,nagios · nagios · CWE-119 | High7.5 | — | 66.5% | Jan 22, 2013 |
40Plan | CVE-2013-7108Proof of concept | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allownagios · nagios · CWE-20 | Medium5.5 | — | 59.5% | Jan 15, 2014 |
40Plan | CVE-2024-49369Proof of concept | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connectionsicinga · icinga · CWE-295 | Critical9.8 | — | 2.9% | Nov 12, 2024 |
39Monitor | CVE-2022-24715Proof of concept | Arbitrary code execution for authenticated users in Icinga Web 2icinga · icinga web 2 · CWE-22 | High8.8 | — | 14.7% | Mar 8, 2022 |
39Monitor | CVE-2018-18249No exploit | Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inficinga · icinga web 2 · CWE-94 | Critical9.8 | — | 1.5% | Dec 17, 2018 |
37Monitor | CVE-2025-48057No exploit | Icinga 2 certificate renewal might incorrectly renew an invalid certificateicinga · icinga · CWE-296 | Critical9.3 | — | 0.4% | May 27, 2025 |
36Monitor | CVE-2021-32743No exploit | Passwords used to access external services inadvertently exposed through APIicinga · icinga · CWE-202 | High8.8 | — | 1.8% | Jul 15, 2021 |
36Monitor | CVE-2020-29663No exploit | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring icinga · icinga · CWE-295 | Critical9.1 | — | 1.6% | Dec 15, 2020 |
35Monitor | CVE-2021-32739No exploit | Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identitiesicinga · icinga · CWE-267 | High8.8 | — | 1.1% | Jul 15, 2021 |
35Monitor | CVE-2023-30607No exploit | icingaweb2-module-jira template and field configuration are susceptible to CSRFicinga · icinga web jira integration · CWE-352 | High8.8 | — | 0.3% | Jul 5, 2023 |
35Monitor | CVE-2024-24819No exploit | icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRFicinga · icingaweb2-module-incubator · CWE-352 | High8.8 | — | 0.3% | Feb 8, 2024 |
33Monitor | CVE-2024-24820No exploit | Icinga Director configuration is susceptible to Cross-Site Request Forgeryicinga · icinga · CWE-352 | High8.3 | — | 0.4% | Feb 8, 2024 |
32Monitor | CVE-2018-6535No exploit | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga | High8.1 | — | 1.3% | Feb 27, 2018 |
31Monitor | CVE-2020-24368No exploit | Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitraryicinga · icinga web 2 · CWE-22 | High7.5 | — | 3.3% | Aug 19, 2020 |
31Monitor | CVE-2012-3441No exploit | The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga useicinga · icinga · CWE-264 | High7.5 | — | 2.4% | Aug 25, 2012 |
31Monitor | CVE-2020-14004No exploit | An issue was discovered in Icinga2 before v2.12.0-rc1.icinga · icinga · CWE-59 | High7.8 | — | 0.7% | Jun 12, 2020 |
31Monitor | CVE-2018-6533No exploit | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga | High7.8 | — | 0.4% | Feb 27, 2018 |
31Monitor | CVE-2017-16882No exploit | Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-rooicinga · icinga · CWE-732 | High7.8 | — | 0.3% | Nov 18, 2017 |
30Monitor | CVE-2021-37698No exploit | Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writericinga · icinga · CWE-295 | High7.5 | — | 1.4% | Aug 19, 2021 |
30Monitor | CVE-2018-6532No exploit | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga · CWE-400 | High7.5 | — | 1.4% | Feb 27, 2018 |
30Monitor | CVE-2018-18250No exploit | Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigicinga · icinga web 2 · CWE-74 | High7.5 | — | 1.0% | Dec 17, 2018 |
28Monitor | CVE-2025-61908No exploit | Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Referenceicinga · icinga · CWE-476 | High7.1 | — | 0.5% | Oct 16, 2025 |
28Monitor | CVE-2025-61907No exploit | Icinga 2 API users could access restricted values in filter expressionsicinga · icinga · CWE-200 | High7.1 | — | 0.4% | Oct 16, 2025 |
28Monitor | CVE-2017-16933No exploit | etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local useicinga · icinga · CWE-732 | High7.0 | — | 0.3% | Nov 24, 2017 |
- CVE-2022-2471657Plan
Path traversal in Icinga Web 2
HighCVSS 7.5WeaponizedEPSS 89%icinga · icinga web 2Mar 8, 2022
- CVE-2012-609650Plan
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,
HighCVSS 7.5WeaponizedEPSS 66%nagios · nagiosJan 22, 2013
- CVE-2013-710840Plan
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow
MediumCVSS 5.5Proof of conceptEPSS 60%nagios · nagiosJan 15, 2014
- CVE-2024-4936940Plan
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
CriticalCVSS 9.8Proof of conceptEPSS 3%icinga · icingaNov 12, 2024
- CVE-2022-2471539Monitor
Arbitrary code execution for authenticated users in Icinga Web 2
HighCVSS 8.8Proof of conceptEPSS 15%icinga · icinga web 2Mar 8, 2022
- CVE-2018-1824939Monitor
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inf
CriticalCVSS 9.8No exploitEPSS 1%icinga · icinga web 2Dec 17, 2018
- CVE-2025-4805737Monitor
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
CriticalCVSS 9.3No exploitEPSS 0%icinga · icingaMay 27, 2025
- CVE-2021-3274336Monitor
Passwords used to access external services inadvertently exposed through API
HighCVSS 8.8No exploitEPSS 2%icinga · icingaJul 15, 2021
- CVE-2020-2966336Monitor
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring
CriticalCVSS 9.1No exploitEPSS 2%icinga · icingaDec 15, 2020
- CVE-2021-3273935Monitor
Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities
HighCVSS 8.8No exploitEPSS 1%icinga · icingaJul 15, 2021
- CVE-2023-3060735Monitor
icingaweb2-module-jira template and field configuration are susceptible to CSRF
HighCVSS 8.8No exploitEPSS 0%icinga · icinga web jira integrationJul 5, 2023
- CVE-2024-2481935Monitor
icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRF
HighCVSS 8.8No exploitEPSS 0%icinga · icingaweb2-module-incubatorFeb 8, 2024
- CVE-2024-2482033Monitor
Icinga Director configuration is susceptible to Cross-Site Request Forgery
HighCVSS 8.3No exploitEPSS 0%icinga · icingaFeb 8, 2024
- CVE-2018-653532Monitor
An issue was discovered in Icinga 2.x through 2.8.1.
HighCVSS 8.1No exploitEPSS 1%icinga · icingaFeb 27, 2018
- CVE-2020-2436831Monitor
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary
HighCVSS 7.5No exploitEPSS 3%icinga · icinga web 2Aug 19, 2020
- CVE-2012-344131Monitor
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga use
HighCVSS 7.5No exploitEPSS 2%icinga · icingaAug 25, 2012
- CVE-2020-1400431Monitor
An issue was discovered in Icinga2 before v2.12.0-rc1.
HighCVSS 7.8No exploitEPSS 1%icinga · icingaJun 12, 2020
- CVE-2018-653331Monitor
An issue was discovered in Icinga 2.x through 2.8.1.
HighCVSS 7.8No exploitEPSS 0%icinga · icingaFeb 27, 2018
- CVE-2017-1688231Monitor
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-roo
HighCVSS 7.8No exploitEPSS 0%icinga · icingaNov 18, 2017
- CVE-2021-3769830Monitor
Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer
HighCVSS 7.5No exploitEPSS 1%icinga · icingaAug 19, 2021
- CVE-2018-653230Monitor
An issue was discovered in Icinga 2.x through 2.8.1.
HighCVSS 7.5No exploitEPSS 1%icinga · icingaFeb 27, 2018
- CVE-2018-1825030Monitor
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navig
HighCVSS 7.5No exploitEPSS 1%icinga · icinga web 2Dec 17, 2018
- CVE-2025-6190828Monitor
Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference
HighCVSS 7.1No exploitEPSS 1%icinga · icingaOct 16, 2025
- CVE-2025-6190728Monitor
Icinga 2 API users could access restricted values in filter expressions
HighCVSS 7.1No exploitEPSS 0%icinga · icingaOct 16, 2025
- CVE-2017-1693328Monitor
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local use
HighCVSS 7.0No exploitEPSS 0%icinga · icingaNov 24, 2017