librenms records
106 published records for vendor librenms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 2.8%
- Pre-auth RCE
- 3
- With a fix record
- 90.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
106 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2018-20434Weaponized | LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.librenms · librenms · CWE-78 | Critical9.8 | — | 71.5% | Apr 24, 2019 |
52Plan | CVE-2019-10669Weaponized | An issue was discovered in LibreNMS through 1.47.librenms · librenms · CWE-78 | High7.2 | — | 80.7% | Sep 9, 2019 |
49Plan | CVE-2022-3562No exploit | Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms · librenms · CWE-79 | Medium5.4 | — | 94.2% | Nov 20, 2022 |
49Plan | CVE-2022-4067No exploit | Cross-site Scripting (XSS) - Stored in librenms/librenmslibrenms · librenms · CWE-79 | Medium5.4 | — | 93.7% | Nov 20, 2022 |
47Plan | CVE-2022-4069No exploit | Cross-site Scripting (XSS) - Generic in librenms/librenmslibrenms · librenms · CWE-79 | Medium4.8 | — | 93.3% | Nov 20, 2022 |
43Plan | CVE-2024-49754No exploit | LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.phplibrenms · librenms · CWE-79 | Medium5.4 | — | 72.4% | Nov 15, 2024 |
42Plan | CVE-2023-4347No exploit | Cross-site Scripting (XSS) - Reflected in librenms/librenmslibrenms · librenms · CWE-79 | Medium5.4 | — | 69.7% | Aug 14, 2023 |
41Plan | CVE-2024-32461No exploit | LibreNMS vulnerable to time-based SQL injection that leads to database extractionlibrenms · librenms · CWE-89 | High8.8 | — | 19.1% | Apr 22, 2024 |
40Plan | CVE-2022-29712No exploit | LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param paramelibrenms · librenms · CWE-77 | Critical9.8 | — | 1.7% | Jun 2, 2022 |
39Monitor | CVE-2021-44278No exploit | Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.librenms · librenms · CWE-22 | Critical9.8 | — | 1.5% | Dec 3, 2021 |
39Monitor | CVE-2019-10665No exploit | An issue was discovered in LibreNMS through 1.47.librenms · librenms · CWE-74 | Critical9.8 | — | 1.5% | Sep 9, 2019 |
39Monitor | CVE-2022-4070No exploit | Insufficient Session Expiration in librenms/librenmslibrenms · librenms · CWE-613 | Critical9.8 | — | 0.6% | Nov 20, 2022 |
38Monitor | CVE-2024-51092Weaponized | LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(),librenms · librenms · CWE-78 | Critical9.1 | — | 7.2% | May 8, 2026 |
37Monitor | CVE-2026-86426Proof of concept | LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusionlibrenms · librenms · CWE-287 | Critical9.2 | — | 3.9% | Sep 7, 2026 |
37Monitor | CVE-2026-26988Proof of concept | LibreNMS: SQL Injection in ajax_table.php spreads through a covert data streamlibrenms · librenms · CWE-89 | Critical9.3 | — | 0.5% | Feb 19, 2026 |
36Monitor | CVE-2020-35700No exploit | A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allolibrenms · librenms · CWE-89 | High8.8 | — | 2.3% | Feb 8, 2021 |
36Monitor | CVE-2020-15877No exploit | An issue was discovered in LibreNMS before 1.65.1.librenms · librenms | High8.8 | — | 1.9% | Jul 21, 2020 |
36Monitor | CVE-2019-10668No exploit | An issue was discovered in LibreNMS through 1.47.librenms · librenms · CWE-306 | Critical9.1 | — | 1.6% | Sep 9, 2019 |
35Monitor | CVE-2019-12463No exploit | An issue was discovered in LibreNMS 1.50.1.librenms · librenms · CWE-74 | High8.8 | — | 1.4% | Sep 9, 2019 |
35Monitor | CVE-2018-20678No exploit | LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during alibrenms · librenms · CWE-89 | High8.8 | — | 1.4% | Mar 28, 2019 |
35Monitor | CVE-2019-10671No exploit | An issue was discovered in LibreNMS through 1.47.librenms · librenms · CWE-89 | High8.8 | — | 1.3% | Sep 9, 2019 |
35Monitor | CVE-2022-0580No exploit | Incorrect Authorization in librenms/librenmslibrenms · librenms · CWE-863 | High8.8 | — | 1.2% | Feb 14, 2022 |
35Monitor | CVE-2022-3525No exploit | Deserialization of Untrusted Data in librenms/librenmslibrenms · librenms · CWE-502 | High8.8 | — | 0.9% | Nov 20, 2022 |
35Monitor | CVE-2026-26990No exploit | LibreNMS has Time-Based Blind SQL Injection in address-search.inc.phplibrenms · librenms · CWE-89 | High8.8 | — | 0.6% | Feb 19, 2026 |
34Monitor | CVE-2024-53457No exploit | A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to executelibrenms · librenms · CWE-79 | Medium5.4 | — | 44.6% | Dec 5, 2024 |
- CVE-2018-2043460This week
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.
CriticalCVSS 9.8WeaponizedEPSS 71%librenms · librenmsApr 24, 2019
- CVE-2019-1066952Plan
An issue was discovered in LibreNMS through 1.47.
HighCVSS 7.2WeaponizedEPSS 81%librenms · librenmsSep 9, 2019
- CVE-2022-356249Plan
Cross-site Scripting (XSS) - Stored in librenms/librenms
MediumCVSS 5.4No exploitEPSS 94%librenms · librenmsNov 20, 2022
- CVE-2022-406749Plan
Cross-site Scripting (XSS) - Stored in librenms/librenms
MediumCVSS 5.4No exploitEPSS 94%librenms · librenmsNov 20, 2022
- CVE-2022-406947Plan
Cross-site Scripting (XSS) - Generic in librenms/librenms
MediumCVSS 4.8No exploitEPSS 93%librenms · librenmsNov 20, 2022
- CVE-2024-4975443Plan
LibreNMS has a stored XSS ('Cross-site Scripting') in librenms/includes/html/pages/api-access.inc.php
MediumCVSS 5.4No exploitEPSS 72%librenms · librenmsNov 15, 2024
- CVE-2023-434742Plan
Cross-site Scripting (XSS) - Reflected in librenms/librenms
MediumCVSS 5.4No exploitEPSS 70%librenms · librenmsAug 14, 2023
- CVE-2024-3246141Plan
LibreNMS vulnerable to time-based SQL injection that leads to database extraction
HighCVSS 8.8No exploitEPSS 19%librenms · librenmsApr 22, 2024
- CVE-2022-2971240Plan
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parame
CriticalCVSS 9.8No exploitEPSS 2%librenms · librenmsJun 2, 2022
- CVE-2021-4427839Monitor
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
CriticalCVSS 9.8No exploitEPSS 1%librenms · librenmsDec 3, 2021
- CVE-2019-1066539Monitor
An issue was discovered in LibreNMS through 1.47.
CriticalCVSS 9.8No exploitEPSS 1%librenms · librenmsSep 9, 2019
- CVE-2022-407039Monitor
Insufficient Session Expiration in librenms/librenms
CriticalCVSS 9.8No exploitEPSS 1%librenms · librenmsNov 20, 2022
- CVE-2024-5109238Monitor
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(),
CriticalCVSS 9.1WeaponizedEPSS 7%librenms · librenmsMay 8, 2026
- CVE-2026-8642637Monitor
LibreNMS before 26.8.0 Authentication Bypass via API Token Type Confusion
CriticalCVSS 9.2Proof of conceptEPSS 4%librenms · librenmsSep 7, 2026
- CVE-2026-2698837Monitor
LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream
CriticalCVSS 9.3Proof of conceptEPSS 0%librenms · librenmsFeb 19, 2026
- CVE-2020-3570036Monitor
A second-order SQL injection issue in Widgets/TopDevicesController.php (aka the Top Devices dashboard widget) of LibreNMS before 21.1.0 allo
HighCVSS 8.8No exploitEPSS 2%librenms · librenmsFeb 8, 2021
- CVE-2020-1587736Monitor
An issue was discovered in LibreNMS before 1.65.1.
HighCVSS 8.8No exploitEPSS 2%librenms · librenmsJul 21, 2020
- CVE-2019-1066836Monitor
An issue was discovered in LibreNMS through 1.47.
CriticalCVSS 9.1No exploitEPSS 2%librenms · librenmsSep 9, 2019
- CVE-2019-1246335Monitor
An issue was discovered in LibreNMS 1.50.1.
HighCVSS 8.8No exploitEPSS 1%librenms · librenmsSep 9, 2019
- CVE-2018-2067835Monitor
LibreNMS through 1.47 allows SQL injection via the html/ajax_table.php sort[hostname] parameter, exploitable by authenticated users during a
HighCVSS 8.8No exploitEPSS 1%librenms · librenmsMar 28, 2019
- CVE-2019-1067135Monitor
An issue was discovered in LibreNMS through 1.47.
HighCVSS 8.8No exploitEPSS 1%librenms · librenmsSep 9, 2019
- CVE-2022-058035Monitor
Incorrect Authorization in librenms/librenms
HighCVSS 8.8No exploitEPSS 1%librenms · librenmsFeb 14, 2022
- CVE-2022-352535Monitor
Deserialization of Untrusted Data in librenms/librenms
HighCVSS 8.8No exploitEPSS 1%librenms · librenmsNov 20, 2022
- CVE-2026-2699035Monitor
LibreNMS has Time-Based Blind SQL Injection in address-search.inc.php
HighCVSS 8.8No exploitEPSS 1%librenms · librenmsFeb 19, 2026
- CVE-2024-5345734Monitor
A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute
MediumCVSS 5.4No exploitEPSS 45%librenms · librenmsDec 5, 2024