op5 records
9 published records for vendor op5.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 22.2%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2012-0261Weaponized | license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commandop5 · monitor · CWE-94 | Critical10.0 | — | 73.9% | Dec 31, 2013 |
62This week | CVE-2012-0262Weaponized | op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrarop5 · monitor · CWE-94 | Critical10.0 | — | 72.9% | Dec 31, 2013 |
41Plan | CVE-2012-0264No exploit | op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impaop5 · monitor · CWE-264 | Critical10.0 | — | 4.4% | Dec 31, 2013 |
28Monitor | CVE-2008-5027No exploit | The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization chenagios · nagios · CWE-264 | Medium6.5 | — | 6.7% | Nov 10, 2008 |
28Monitor | CVE-2008-5028No exploit | Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to snagios · nagios · CWE-352 | Medium6.8 | — | 1.7% | Nov 10, 2008 |
24Monitor | CVE-2021-40272Proof of concept | OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).op5 · monitor · CWE-79 | Medium6.1 | — | 1.1% | Nov 14, 2022 |
20Monitor | CVE-2013-6141No exploit | Unspecified vulnerability in op5 Monitor before 6.1.3 allows attackers to read arbitrary files via unknown vectors related to lack of authorop5 · monitor | Medium5.0 | — | 1.0% | Jan 29, 2014 |
18Monitor | CVE-2014-4907No exploit | Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attapnp4nagios · pnp4nagios · CWE-79 | Medium4.3 | — | 2.2% | Jul 11, 2014 |
17Monitor | CVE-2012-0263No exploit | monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as daop5 · monitor · CWE-200 | Medium4.0 | — | 1.9% | Dec 31, 2013 |
- CVE-2012-026162This week
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary command
CriticalCVSS 10.0WeaponizedEPSS 74%op5 · monitorDec 31, 2013
- CVE-2012-026262This week
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrar
CriticalCVSS 10.0WeaponizedEPSS 73%op5 · monitorDec 31, 2013
- CVE-2012-026441Plan
op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impa
CriticalCVSS 10.0No exploitEPSS 4%op5 · monitorDec 31, 2013
- CVE-2008-502728Monitor
The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization che
MediumCVSS 6.5No exploitEPSS 7%nagios · nagiosNov 10, 2008
- CVE-2008-502828Monitor
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to s
MediumCVSS 6.8No exploitEPSS 2%nagios · nagiosNov 10, 2008
- CVE-2021-4027224Monitor
OP5 Monitor 8.3.1, 8.3.2, and OP5 8.3.3 are vulnerable to Cross Site Scripting (XSS).
MediumCVSS 6.1Proof of conceptEPSS 1%op5 · monitorNov 14, 2022
- CVE-2013-614120Monitor
Unspecified vulnerability in op5 Monitor before 6.1.3 allows attackers to read arbitrary files via unknown vectors related to lack of author
MediumCVSS 5.0No exploitEPSS 1%op5 · monitorJan 29, 2014
- CVE-2014-490718Monitor
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote atta
MediumCVSS 4.3No exploitEPSS 2%pnp4nagios · pnp4nagiosJul 11, 2014
- CVE-2012-026317Monitor
monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as da
MediumCVSS 4.0No exploitEPSS 2%op5 · monitorDec 31, 2013