netdata records
5 published records for vendor netdata.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 20%
- Pre-auth RCE
- 1
- With a fix record
- 60%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-426 Untrusted Search Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2023-22496Proof of concept | Netdata vulnerable to command injectionnetdata · netdata · CWE-20 | Critical9.8 | — | 36.2% | Jan 13, 2023 |
36Monitor | CVE-2023-22497No exploit | Netdata is vulnerable to improper authenticationnetdata · netdata · CWE-287 | Critical9.1 | — | 0.7% | Jan 13, 2023 |
35Monitor | CVE-2024-32019Weaponized | ndsudo: local privilege escalation via untrusted search pathnetdata · netdata · CWE-426 | High8.8 | — | 1.2% | Apr 12, 2024 |
26Monitor | CVE-2019-9834Proof of concept | The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTnetdata · netdata · CWE-79 | Medium6.1 | — | 6.2% | Mar 15, 2019 |
20Monitor | CVE-2025-71385No exploit | Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.svg Endpointnetdata · netdata · CWE-79 | Medium5.1 | — | 0.4% | Jul 2, 2026 |
- CVE-2023-2249650Plan
Netdata vulnerable to command injection
CriticalCVSS 9.8Proof of conceptEPSS 36%netdata · netdataJan 13, 2023
- CVE-2023-2249736Monitor
Netdata is vulnerable to improper authentication
CriticalCVSS 9.1No exploitEPSS 1%netdata · netdataJan 13, 2023
- CVE-2024-3201935Monitor
ndsudo: local privilege escalation via untrusted search path
HighCVSS 8.8WeaponizedEPSS 1%netdata · netdataApr 12, 2024
- CVE-2019-983426Monitor
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HT
MediumCVSS 6.1Proof of conceptEPSS 6%netdata · netdataMar 15, 2019
- CVE-2025-7138520Monitor
Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.svg Endpoint
MediumCVSS 5.1No exploitEPSS 0%netdata · netdataJul 2, 2026