CVE-2024-43363
- EPSS 47.48%
- Published 07.10.2024 21:15:15
- Last modified 17.10.2024 17:58:55
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no ...
CVE-2024-34340
- EPSS 0.79%
- Published 14.05.2024 15:38:39
- Last modified 18.12.2024 20:44:22
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verify...
CVE-2024-31459
- EPSS 3.63%
- Published 14.05.2024 15:25:26
- Last modified 18.12.2024 20:49:57
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. The...
CVE-2024-31460
- EPSS 1.08%
- Published 14.05.2024 15:25:26
- Last modified 18.12.2024 20:38:39
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_node...
- EPSS 3.56%
- Published 14.05.2024 15:25:25
- Last modified 18.12.2024 20:47:06
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement ...
CVE-2024-31445
- EPSS 42.3%
- Published 14.05.2024 15:25:21
- Last modified 18.12.2024 18:29:21
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL inject...
CVE-2024-31443
- EPSS 0.35%
- Published 14.05.2024 15:25:20
- Last modified 18.12.2024 18:28:19
Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_p...
CVE-2024-31444
- EPSS 5.42%
- Published 14.05.2024 15:25:20
- Last modified 18.12.2024 18:28:58
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concaten...
CVE-2024-30268
- EPSS 0.2%
- Published 14.05.2024 15:22:18
- Last modified 21.11.2024 09:11:35
Cacti provides an operational monitoring and fault management framework. A reflected cross-site scripting vulnerability on the 1.3.x DEV branch allows attackers to obtain cookies of administrator and other users and fake their login using obtained co...
- EPSS 93.14%
- Published 14.05.2024 15:17:15
- Last modified 21.11.2024 09:08:34
Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option of PHP is `...