Opsview records
16 published records for vendor opsview.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-732 Incorrect Permission Assignment for Critical Resource1
- CWE-20 Improper Input Validation1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2018-16144No exploit | The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command inopsview · opsview · CWE-78 | Critical9.8 | — | 32.7% | Sep 5, 2018 |
35Monitor | CVE-2016-10367Proof of concept | In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security opsview · opsview · CWE-22 | High7.5 | — | 16.1% | May 3, 2017 |
35Monitor | CVE-2013-3935No exploit | Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack topsview · opsview · CWE-352 | High8.8 | — | 0.5% | Jan 2, 2020 |
33Monitor | CVE-2018-16145No exploit | The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a fileopsview · opsview · CWE-732 | High8.1 | — | 2.3% | Sep 5, 2018 |
31Monitor | CVE-2013-5694Proof of concept | SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands opsview · opsview · CWE-89 | High7.5 | — | 2.6% | Nov 5, 2013 |
30Monitor | CVE-2018-16146No exploit | The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to testopsview · opsview · CWE-78 | High7.2 | — | 6.2% | Sep 5, 2018 |
27Monitor | CVE-2013-7256No exploit | Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified opsview · opsview · CWE-352 | Medium6.8 | — | 0.6% | Jan 3, 2014 |
25Monitor | CVE-2016-10368Proof of concept | Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x withopsview · opsview · CWE-601 | Medium6.1 | — | 2.2% | May 3, 2017 |
24Monitor | CVE-2018-16148No exploit | The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scriopsview · opsview · CWE-79 | Medium6.1 | — | 1.3% | Sep 5, 2018 |
24Monitor | CVE-2018-16147No exploit | The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Sopsview · opsview · CWE-79 | Medium6.1 | — | 1.3% | Sep 5, 2018 |
24Monitor | CVE-2013-3936No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to injecopsview · opsview · CWE-79 | Medium6.1 | — | 0.8% | Jan 2, 2020 |
24Monitor | CVE-2015-6035No exploit | Opsview before 2015-11-06 has XSS via SNMP.opsview · opsview · CWE-79 | Medium6.1 | — | 0.7% | Apr 9, 2017 |
23Monitor | CVE-2013-7255No exploit | Open redirect vulnerability in Opsview before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing atopsview · opsview · CWE-20 | Medium5.8 | — | 1.2% | Jan 3, 2014 |
17Monitor | CVE-2015-4420Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTopsview · opsview · CWE-79 | Medium4.3 | — | 1.5% | Jun 18, 2015 |
17Monitor | CVE-2013-7254No exploit | Cross-site scripting (XSS) vulnerability in Opsview before 4.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecifopsview · opsview · CWE-79 | Medium4.3 | — | 1.1% | Jan 3, 2014 |
17Monitor | CVE-2013-5695No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML viopsview · opsview · CWE-79 | Medium4.3 | — | 1.0% | Nov 5, 2013 |
- CVE-2018-1614449Plan
The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command in
CriticalCVSS 9.8No exploitEPSS 33%opsview · opsviewSep 5, 2018
- CVE-2016-1036735Monitor
In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security
HighCVSS 7.5Proof of conceptEPSS 16%opsview · opsviewMay 3, 2017
- CVE-2013-393535Monitor
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack t
HighCVSS 8.8No exploitEPSS 1%opsview · opsviewJan 2, 2020
- CVE-2018-1614533Monitor
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file
HighCVSS 8.1No exploitEPSS 2%opsview · opsviewSep 5, 2018
- CVE-2013-569431Monitor
SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5Proof of conceptEPSS 3%opsview · opsviewNov 5, 2013
- CVE-2018-1614630Monitor
The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test
HighCVSS 7.2No exploitEPSS 6%opsview · opsviewSep 5, 2018
- CVE-2013-725627Monitor
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified
MediumCVSS 6.8No exploitEPSS 1%opsview · opsviewJan 3, 2014
- CVE-2016-1036825Monitor
Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x with
MediumCVSS 6.1Proof of conceptEPSS 2%opsview · opsviewMay 3, 2017
- CVE-2018-1614824Monitor
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scri
MediumCVSS 6.1No exploitEPSS 1%opsview · opsviewSep 5, 2018
- CVE-2018-1614724Monitor
The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site S
MediumCVSS 6.1No exploitEPSS 1%opsview · opsviewSep 5, 2018
- CVE-2013-393624Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to injec
MediumCVSS 6.1No exploitEPSS 1%opsview · opsviewJan 2, 2020
- CVE-2015-603524Monitor
Opsview before 2015-11-06 has XSS via SNMP.
MediumCVSS 6.1No exploitEPSS 1%opsview · opsviewApr 9, 2017
- CVE-2013-725523Monitor
Open redirect vulnerability in Opsview before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at
MediumCVSS 5.8No exploitEPSS 1%opsview · opsviewJan 3, 2014
- CVE-2015-442017Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HT
MediumCVSS 4.3Proof of conceptEPSS 2%opsview · opsviewJun 18, 2015
- CVE-2013-725417Monitor
Cross-site scripting (XSS) vulnerability in Opsview before 4.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecif
MediumCVSS 4.3No exploitEPSS 1%opsview · opsviewJan 3, 2014
- CVE-2013-569517Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 1%opsview · opsviewNov 5, 2013