CVE-2026-24413
- EPSS 0.01%
- Veröffentlicht 29.01.2026 17:21:01
- Zuletzt bearbeitet 29.01.2026 18:54:13
Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in th...
CVE-2025-61909
- EPSS 0.02%
- Veröffentlicht 16.10.2025 17:20:14
- Zuletzt bearbeitet 29.10.2025 20:03:42
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 pr...
CVE-2025-61908
- EPSS 0.07%
- Veröffentlicht 16.10.2025 17:16:58
- Zuletzt bearbeitet 26.11.2025 14:57:15
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with acc...
CVE-2025-61907
- EPSS 0.04%
- Veröffentlicht 16.10.2025 17:11:59
- Zuletzt bearbeitet 26.11.2025 15:04:24
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows a...
CVE-2025-48057
- EPSS 0.05%
- Veröffentlicht 27.05.2025 16:32:29
- Zuletzt bearbeitet 05.12.2025 00:12:22
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be trick...
CVE-2024-49369
- EPSS 20.46%
- Veröffentlicht 12.11.2024 17:15:08
- Zuletzt bearbeitet 26.11.2025 13:01:15
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowin...
CVE-2024-24820
- EPSS 0.07%
- Veröffentlicht 09.02.2024 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:59:47
Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attack...
CVE-2021-37698
- EPSS 0.16%
- Veröffentlicht 19.08.2021 16:15:12
- Zuletzt bearbeitet 03.11.2025 22:15:49
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2...
CVE-2021-32743
- EPSS 0.35%
- Veröffentlicht 15.07.2021 16:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:48
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga...
CVE-2021-32739
- EPSS 0.3%
- Veröffentlicht 15.07.2021 15:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:48
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege esca...