Centreon kayıtları
centreon üreticisine ait 127 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %1,6
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %25,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')51
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')31
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-425 Direct Request ('Forced Browsing')4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
127 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2022-41142İstismar yok | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Yüksek8,8 | — | %85,0 | 26 Oca 2023 |
58Planlayın | CVE-2022-42425İstismar yok | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Yüksek8,8 | — | %76,1 | 29 Mar 2023 |
58Planlayın | CVE-2022-42427İstismar yok | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Yüksek8,8 | — | %76,1 | 29 Mar 2023 |
58Planlayın | CVE-2022-42424İstismar yok | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Yüksek8,8 | — | %76,1 | 29 Mar 2023 |
58Planlayın | CVE-2022-42429İstismar yok | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.centreon · centreon · CWE-89 | Yüksek8,8 | — | %76,1 | 29 Mar 2023 |
57Planlayın | CVE-2024-0637İstismar yok | Centreon updateDirectory SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek8,8 | — | %72,3 | 1 Nis 2024 |
49Planlayın | CVE-2024-5725İstismar yok | Centreon initCurveList SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek8,8 | — | %47,4 | 21 Ağu 2024 |
48Planlayın | CVE-2024-23115İstismar yok | Centreon updateGroups SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek7,2 | — | %67,5 | 1 Nis 2024 |
47Planlayın | CVE-2024-5723İstismar yok | Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek8,8 | — | %40,7 | 21 Ağu 2024 |
45Planlayın | CVE-2019-13024Kavram kanıtı | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands bcentreon · centreon · CWE-77 | Yüksek8,8 | — | %32,2 | 1 Tem 2019 |
45Planlayın | CVE-2024-32501İstismar yok | A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,centreon · centreon web · CWE-89 | Kritik9,8 | — | %19,2 | 23 Ağu 2024 |
44Planlayın | CVE-2024-23117İstismar yok | Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek7,2 | — | %53,4 | 1 Nis 2024 |
44Planlayın | CVE-2024-23118İstismar yok | Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek7,2 | — | %53,4 | 1 Nis 2024 |
44Planlayın | CVE-2024-23116İstismar yok | Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerabilitycentreon · centreon web · CWE-89 | Yüksek7,2 | — | %53,4 | 1 Nis 2024 |
43Planlayın | CVE-2021-37557İstismar yok | A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pricentreon · centreon · CWE-89 | Yüksek8,8 | — | %27,4 | 3 Ağu 2021 |
43Planlayın | CVE-2021-37556İstismar yok | A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pricentreon · centreon · CWE-89 | Yüksek8,8 | — | %27,4 | 3 Ağu 2021 |
43Planlayın | CVE-2019-15298İstismar yok | A problem was found in Centreon Web through 19.04.3.centreon · centreon web · CWE-78 | Yüksek8,8 | — | %26,6 | 27 Kas 2019 |
43Planlayın | CVE-2025-15029İstismar yok | An unauthenticated user is able to introduce SQL Injection using the Awie export modulecentreon · awie · CWE-89 | Kritik9,8 | — | %12,7 | 5 Oca 2026 |
40Planlayın | CVE-2018-11587İstismar yok | There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraphcentreon · centreon · CWE-94 | Kritik9,8 | — | %4,2 | 25 Haz 2018 |
40Planlayın | CVE-2018-21025İstismar yok | In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced centreon · centreon vm · CWE-269 | Kritik9,8 | — | %2,8 | 8 Eki 2019 |
40Planlayın | CVE-2018-21024İstismar yok | licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.centreon · centreon · CWE-434 | Kritik9,8 | — | %2,2 | 8 Eki 2019 |
40Planlayın | CVE-2018-11589İstismar yok | Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.pcentreon · centreon · CWE-89 | Kritik9,8 | — | %2,1 | 25 Haz 2018 |
40Planlayın | CVE-2021-37558İstismar yok | A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attackercentreon · centreon · CWE-89 | Kritik9,8 | — | %2,1 | 3 Ağu 2021 |
40Planlayın | CVE-2019-17647İstismar yok | An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.centreon · centreon · CWE-89 | Kritik9,8 | — | %1,8 | 5 Mar 2020 |
40Planlayın | CVE-2018-19281İstismar yok | Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.centreon · centreon · CWE-89 | Kritik9,8 | — | %1,8 | 14 Kas 2018 |
- CVE-2022-4114261Bu hafta
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
YüksekCVSS 8,8İstismar yokEPSS %85centreon · centreon26 Oca 2023
- CVE-2022-4242558Planlayın
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
YüksekCVSS 8,8İstismar yokEPSS %76centreon · centreon29 Mar 2023
- CVE-2022-4242758Planlayın
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
YüksekCVSS 8,8İstismar yokEPSS %76centreon · centreon29 Mar 2023
- CVE-2022-4242458Planlayın
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
YüksekCVSS 8,8İstismar yokEPSS %76centreon · centreon29 Mar 2023
- CVE-2022-4242958Planlayın
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.
YüksekCVSS 8,8İstismar yokEPSS %76centreon · centreon29 Mar 2023
- CVE-2024-063757Planlayın
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %72centreon · centreon web1 Nis 2024
- CVE-2024-572549Planlayın
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %47centreon · centreon web21 Ağu 2024
- CVE-2024-2311548Planlayın
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %67centreon · centreon web1 Nis 2024
- CVE-2024-572347Planlayın
Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %41centreon · centreon web21 Ağu 2024
- CVE-2019-1302445Planlayın
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands b
YüksekCVSS 8,8Kavram kanıtıEPSS %32centreon · centreon1 Tem 2019
- CVE-2024-3250145Planlayın
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13,
KritikCVSS 9,8İstismar yokEPSS %19centreon · centreon web23 Ağu 2024
- CVE-2024-2311744Planlayın
Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %53centreon · centreon web1 Nis 2024
- CVE-2024-2311844Planlayın
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %53centreon · centreon web1 Nis 2024
- CVE-2024-2311644Planlayın
Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %53centreon · centreon web1 Nis 2024
- CVE-2021-3755743Planlayın
A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pri
YüksekCVSS 8,8İstismar yokEPSS %27centreon · centreon3 Ağu 2021
- CVE-2021-3755643Planlayın
A SQL injection vulnerability in reporting export in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-pri
YüksekCVSS 8,8İstismar yokEPSS %27centreon · centreon3 Ağu 2021
- CVE-2019-1529843Planlayın
A problem was found in Centreon Web through 19.04.3.
YüksekCVSS 8,8İstismar yokEPSS %27centreon · centreon web27 Kas 2019
- CVE-2025-1502943Planlayın
An unauthenticated user is able to introduce SQL Injection using the Awie export module
KritikCVSS 9,8İstismar yokEPSS %13centreon · awie5 Oca 2026
- CVE-2018-1158740Planlayın
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph
KritikCVSS 9,8İstismar yokEPSS %4centreon · centreon25 Haz 2018
- CVE-2018-2102540Planlayın
In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced
KritikCVSS 9,8İstismar yokEPSS %3centreon · centreon vm8 Eki 2019
- CVE-2018-2102440Planlayın
licenseUpload.php in Centreon Web before 2.8.27 allows attackers to upload arbitrary files via a POST request.
KritikCVSS 9,8İstismar yokEPSS %2centreon · centreon8 Eki 2019
- CVE-2018-1158940Planlayın
Multiple SQL injection vulnerabilities in Centreon 3.4.6 including Centreon Web 2.8.23 allow attacks via the searchU parameter in viewLogs.p
KritikCVSS 9,8İstismar yokEPSS %2centreon · centreon25 Haz 2018
- CVE-2021-3755840Planlayın
A SQL injection vulnerability in a MediaWiki script in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote unauthenticated attacker
KritikCVSS 9,8İstismar yokEPSS %2centreon · centreon3 Ağu 2021
- CVE-2019-1764740Planlayın
An issue was discovered in Centreon before 2.8.30, 18.10.8, 19.04.5, and 19.10.2.
KritikCVSS 9,8İstismar yokEPSS %2centreon · centreon5 Mar 2020
- CVE-2018-1928140Planlayın
Centreon 3.4.x (fixed in Centreon 18.10.0 and Centreon web 2.8.27) allows SNMP trap SQL Injection.
KritikCVSS 9,8İstismar yokEPSS %2centreon · centreon14 Kas 2018