İçeriğe atla
Noroxi

Icinga kayıtları

icinga üreticisine ait 49 yayımlanmış kayıt.

Tüm kayıtlar

49 kayıt
  • CVE-2022-24716
    57Planlayın

    Path traversal in Icinga Web 2

    YüksekCVSS 7,5SilahlaştırılmışEPSS %89

    icinga · icinga web 28 Mar 2022

  • CVE-2012-6096
    50Planlayın

    Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,

    YüksekCVSS 7,5SilahlaştırılmışEPSS %66

    nagios · nagios22 Oca 2013

  • CVE-2013-7108
    40Planlayın

    Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow

    OrtaCVSS 5,5Kavram kanıtıEPSS %60

    nagios · nagios15 Oca 2014

  • CVE-2024-49369
    40Planlayın

    Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    icinga · icinga12 Kas 2024

  • CVE-2022-24715
    39İzleyin

    Arbitrary code execution for authenticated users in Icinga Web 2

    YüksekCVSS 8,8Kavram kanıtıEPSS %15

    icinga · icinga web 28 Mar 2022

  • CVE-2018-18249
    39İzleyin

    Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inf

    KritikCVSS 9,8İstismar yokEPSS %1

    icinga · icinga web 217 Ara 2018

  • CVE-2025-48057
    37İzleyin

    Icinga 2 certificate renewal might incorrectly renew an invalid certificate

    KritikCVSS 9,3İstismar yokEPSS %0

    icinga · icinga27 May 2025

  • CVE-2021-32743
    36İzleyin

    Passwords used to access external services inadvertently exposed through API

    YüksekCVSS 8,8İstismar yokEPSS %2

    icinga · icinga15 Tem 2021

  • CVE-2020-29663
    36İzleyin

    Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring

    KritikCVSS 9,1İstismar yokEPSS %2

    icinga · icinga15 Ara 2020

  • CVE-2021-32739
    35İzleyin

    Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities

    YüksekCVSS 8,8İstismar yokEPSS %1

    icinga · icinga15 Tem 2021

  • CVE-2023-30607
    35İzleyin

    icingaweb2-module-jira template and field configuration are susceptible to CSRF

    YüksekCVSS 8,8İstismar yokEPSS %0

    icinga · icinga web jira integration5 Tem 2023

  • CVE-2024-24819
    35İzleyin

    icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRF

    YüksekCVSS 8,8İstismar yokEPSS %0

    icinga · icingaweb2-module-incubator8 Şub 2024

  • CVE-2024-24820
    33İzleyin

    Icinga Director configuration is susceptible to Cross-Site Request Forgery

    YüksekCVSS 8,3İstismar yokEPSS %0

    icinga · icinga8 Şub 2024

  • CVE-2018-6535
    32İzleyin

    An issue was discovered in Icinga 2.x through 2.8.1.

    YüksekCVSS 8,1İstismar yokEPSS %1

    icinga · icinga27 Şub 2018

  • CVE-2020-24368
    31İzleyin

    Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary

    YüksekCVSS 7,5İstismar yokEPSS %3

    icinga · icinga web 219 Ağu 2020

  • CVE-2012-3441
    31İzleyin

    The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga use

    YüksekCVSS 7,5İstismar yokEPSS %2

    icinga · icinga25 Ağu 2012

  • CVE-2020-14004
    31İzleyin

    An issue was discovered in Icinga2 before v2.12.0-rc1.

    YüksekCVSS 7,8İstismar yokEPSS %1

    icinga · icinga12 Haz 2020

  • CVE-2018-6533
    31İzleyin

    An issue was discovered in Icinga 2.x through 2.8.1.

    YüksekCVSS 7,8İstismar yokEPSS %0

    icinga · icinga27 Şub 2018

  • CVE-2017-16882
    31İzleyin

    Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-roo

    YüksekCVSS 7,8İstismar yokEPSS %0

    icinga · icinga18 Kas 2017

  • CVE-2021-37698
    30İzleyin

    Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer

    YüksekCVSS 7,5İstismar yokEPSS %1

    icinga · icinga19 Ağu 2021

  • CVE-2018-6532
    30İzleyin

    An issue was discovered in Icinga 2.x through 2.8.1.

    YüksekCVSS 7,5İstismar yokEPSS %1

    icinga · icinga27 Şub 2018

  • CVE-2018-18250
    30İzleyin

    Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navig

    YüksekCVSS 7,5İstismar yokEPSS %1

    icinga · icinga web 217 Ara 2018

  • CVE-2025-61908
    28İzleyin

    Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference

    YüksekCVSS 7,1İstismar yokEPSS %1

    icinga · icinga16 Eki 2025

  • CVE-2025-61907
    28İzleyin

    Icinga 2 API users could access restricted values in filter expressions

    YüksekCVSS 7,1İstismar yokEPSS %0

    icinga · icinga16 Eki 2025

  • CVE-2017-16933
    28İzleyin

    etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local use

    YüksekCVSS 7,0İstismar yokEPSS %0

    icinga · icinga24 Kas 2017