Записи Cacti
155 опубликованных записей вендора cacti.
Профиль для исследователя
- Попали в KEV
- 1 · 0,6 %
- С эксплойтом
- 7 · 4,5 %
- Pre-auth RCE
- 23
- С записью об исправлении
- 97,4 %
- Медиана: публикация → KEV
- 73 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')62
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')42
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')5
- CWE-20 Improper Input Validation4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
155 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2022-46169Готовый эксплойт | Unauthenticated Command Injectioncacti · cacti · CWE-74 | Критическая9,8 | KEV | 99,8 % | 5 дек. 2022 г. |
70На этой неделе | CVE-2024-29895Proof of concept | Cacti command injection in cmd_realtime.phpcacti · cacti · CWE-77 | Критическая10,0 | — | 98,5 % | 14 мая 2024 г. |
66На этой неделе | CVE-2023-39361Proof of concept | Unauthenticated SQL Injection in graph_view.php in Cacticacti · cacti · CWE-89 | Критическая9,8 | — | 88,8 % | 5 сент. 2023 г. |
57В плане | CVE-2023-49085Готовый эксплойт | Cacti SQL Injection vulnerabilitycacti · cacti · CWE-89 | Высокая8,8 | — | 74,5 % | 22 дек. 2023 г. |
57В плане | CVE-2020-8813Proof of concept | graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest cacti · cacti · CWE-78 | Высокая8,8 | — | 74,0 % | 21 февр. 2020 г. |
55В плане | CVE-2023-51448Эксплойта нет | SQL Injection vulnerability when managing SNMP Notification Receiverscacti · cacti · CWE-89 | Высокая8,8 | — | 67,3 % | 22 дек. 2023 г. |
54В плане | CVE-2020-14295Готовый эксплойт | A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.cacti · cacti · CWE-89 | Высокая7,2 | — | 86,3 % | 17 июн. 2020 г. |
54В плане | CVE-2024-25641Готовый эксплойт | Cacti RCE vulnerability when importing packagescacti · cacti · CWE-20 | Высокая7,2 | — | 86,3 % | 14 мая 2024 г. |
54В плане | CVE-2023-39362Proof of concept | Authenticated command injection in SNMP options of a Devicecacti · cacti · CWE-78 | Высокая7,2 | — | 85,4 % | 5 сент. 2023 г. |
54В плане | CVE-2023-49084Готовый эксплойт | Local File Inclusion (RCE) in Cacticacti · cacti · CWE-98 | Высокая8,8 | — | 64,4 % | 21 дек. 2023 г. |
50В плане | CVE-2025-24367Готовый эксплойт | Cacti allows Arbitrary File Creation leading to RCEcacti · cacti · CWE-144 | Высокая8,7 | — | 54,0 % | 27 янв. 2025 г. |
47В плане | CVE-2024-54146Эксплойта нет | Cacti has a SQL Injection vulnerability when view host templatecacti · cacti · CWE-89 | Высокая8,8 | — | 41,0 % | 27 янв. 2025 г. |
46В плане | CVE-2020-7237Эксплойта нет | Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_acacti · cacti · CWE-78 | Высокая8,8 | — | 37,1 % | 20 янв. 2020 г. |
43В плане | CVE-2024-43364Эксплойта нет | Stored Cross-site Scripting (XSS) when creating external links in Cacticacti · cacti · CWE-79 | Высокая8,2 | — | 37,9 % | 7 окт. 2024 г. |
43В плане | CVE-2024-31445Эксплойта нет | SQL Injection vulnerability in automation_get_new_graphs_sqlcacti · cacti · CWE-89 | Высокая8,8 | — | 26,2 % | 14 мая 2024 г. |
40В плане | CVE-2024-43365Эксплойта нет | Stored Cross-site Scripting (XSS) when creating external links in Cacticacti · cacti · CWE-79 | Высокая8,2 | — | 25,1 % | 7 окт. 2024 г. |
40В плане | CVE-2022-0730Эксплойта нет | Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.cacti · cacti · CWE-287 | Критическая9,8 | — | 3,5 % | 3 мар. 2022 г. |
40В плане | CVE-2017-12065Эксплойта нет | spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end pacacti · cacti | Критическая9,8 | — | 2,9 % | 1 авг. 2017 г. |
39Наблюдать | CVE-2024-43363Proof of concept | Remote code execution via Log Poisoning in Cacticacti · cacti · CWE-94 | Высокая7,2 | — | 35,6 % | 7 окт. 2024 г. |
39Наблюдать | CVE-2009-4112Proof of concept | Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux -cacti · cacti · CWE-264 | Критическая9,0 | — | 11,5 % | 30 нояб. 2009 г. |
39Наблюдать | CVE-2026-39938Proof of concept | Cacti: Unauthenticated RCE on Graph Imagecacti · cacti · CWE-22 | Критическая9,8 | — | 0,7 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2026-39893Эксплойта нет | Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.phpcacti · cacti · CWE-89 | Критическая9,8 | — | 0,7 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2026-39955Эксплойта нет | Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.phpcacti · cacti · CWE-89 | Критическая9,8 | — | 0,6 % | 24 июн. 2026 г. |
39Наблюдать | CVE-2025-26520Эксплойта нет | Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter.cacti · cacti · CWE-89 | Критическая9,8 | — | 0,5 % | 12 февр. 2025 г. |
37Наблюдать | CVE-2026-39948Эксплойта нет | Cacti has SQL Injection via rfilter parameter in RLIKE clausescacti · cacti · CWE-89 | Критическая9,3 | — | 0,8 % | 24 июн. 2026 г. |
- CVE-2022-4616999Срочно
Unauthenticated Command Injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %cacti · cacti5 дек. 2022 г.
- CVE-2024-2989570На этой неделе
Cacti command injection in cmd_realtime.php
КритическаяCVSS 10,0Proof of conceptEPSS 98 %cacti · cacti14 мая 2024 г.
- CVE-2023-3936166На этой неделе
Unauthenticated SQL Injection in graph_view.php in Cacti
КритическаяCVSS 9,8Proof of conceptEPSS 89 %cacti · cacti5 сент. 2023 г.
- CVE-2023-4908557В плане
Cacti SQL Injection vulnerability
ВысокаяCVSS 8,8Готовый эксплойтEPSS 74 %cacti · cacti22 дек. 2023 г.
- CVE-2020-881357В плане
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest
ВысокаяCVSS 8,8Proof of conceptEPSS 74 %cacti · cacti21 февр. 2020 г.
- CVE-2023-5144855В плане
SQL Injection vulnerability when managing SNMP Notification Receivers
ВысокаяCVSS 8,8Эксплойта нетEPSS 67 %cacti · cacti22 дек. 2023 г.
- CVE-2020-1429554В плане
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter.
ВысокаяCVSS 7,2Готовый эксплойтEPSS 86 %cacti · cacti17 июн. 2020 г.
- CVE-2024-2564154В плане
Cacti RCE vulnerability when importing packages
ВысокаяCVSS 7,2Готовый эксплойтEPSS 86 %cacti · cacti14 мая 2024 г.
- CVE-2023-3936254В плане
Authenticated command injection in SNMP options of a Device
ВысокаяCVSS 7,2Proof of conceptEPSS 85 %cacti · cacti5 сент. 2023 г.
- CVE-2023-4908454В плане
Local File Inclusion (RCE) in Cacti
ВысокаяCVSS 8,8Готовый эксплойтEPSS 64 %cacti · cacti21 дек. 2023 г.
- CVE-2025-2436750В плане
Cacti allows Arbitrary File Creation leading to RCE
ВысокаяCVSS 8,7Готовый эксплойтEPSS 54 %cacti · cacti27 янв. 2025 г.
- CVE-2024-5414647В плане
Cacti has a SQL Injection vulnerability when view host template
ВысокаяCVSS 8,8Эксплойта нетEPSS 41 %cacti · cacti27 янв. 2025 г.
- CVE-2020-723746В плане
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_a
ВысокаяCVSS 8,8Эксплойта нетEPSS 37 %cacti · cacti20 янв. 2020 г.
- CVE-2024-4336443В плане
Stored Cross-site Scripting (XSS) when creating external links in Cacti
ВысокаяCVSS 8,2Эксплойта нетEPSS 38 %cacti · cacti7 окт. 2024 г.
- CVE-2024-3144543В плане
SQL Injection vulnerability in automation_get_new_graphs_sql
ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %cacti · cacti14 мая 2024 г.
- CVE-2024-4336540В плане
Stored Cross-site Scripting (XSS) when creating external links in Cacti
ВысокаяCVSS 8,2Эксплойта нетEPSS 25 %cacti · cacti7 окт. 2024 г.
- CVE-2022-073040В плане
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cacti · cacti3 мар. 2022 г.
- CVE-2017-1206540В плане
spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end pa
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cacti · cacti1 авг. 2017 г.
- CVE-2024-4336339Наблюдать
Remote code execution via Log Poisoning in Cacti
ВысокаяCVSS 7,2Proof of conceptEPSS 36 %cacti · cacti7 окт. 2024 г.
- CVE-2009-411239Наблюдать
Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux -
КритическаяCVSS 9,0Proof of conceptEPSS 11 %cacti · cacti30 нояб. 2009 г.
- CVE-2026-3993839Наблюдать
Cacti: Unauthenticated RCE on Graph Image
КритическаяCVSS 9,8Proof of conceptEPSS 1 %cacti · cacti24 июн. 2026 г.
- CVE-2026-3989339Наблюдать
Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cacti · cacti24 июн. 2026 г.
- CVE-2026-3995539Наблюдать
Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cacti · cacti24 июн. 2026 г.
- CVE-2025-2652039Наблюдать
Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %cacti · cacti12 февр. 2025 г.
- CVE-2026-3994837Наблюдать
Cacti has SQL Injection via rfilter parameter in RLIKE clauses
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %cacti · cacti24 июн. 2026 г.