Cacti

Cacti

137 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.51%
  • Published 06.09.2023 18:15:08
  • Last modified 10.04.2025 20:43:41

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. Thes...

Exploit
  • EPSS 0.17%
  • Published 05.09.2023 22:15:09
  • Last modified 13.02.2025 17:16:52

Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has bee...

Exploit
  • EPSS 0.26%
  • Published 05.09.2023 22:15:09
  • Last modified 10.04.2025 20:51:38

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. Thes...

Exploit
  • EPSS 35.52%
  • Published 05.09.2023 22:15:08
  • Last modified 11.04.2025 14:48:45

Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadg...

Exploit
  • EPSS 0.12%
  • Published 05.09.2023 22:15:08
  • Last modified 11.04.2025 14:17:51

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a privilege escalation vulnerability. A low-privileged OS user with access to a Windows host where Cacti is installed can create arbitrary...

Exploit
  • EPSS 1.7%
  • Published 05.09.2023 22:15:08
  • Last modified 21.11.2024 08:15:13

Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the...

Exploit
  • EPSS 3.99%
  • Published 05.09.2023 22:15:08
  • Last modified 21.11.2024 08:15:13

Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability r...

Exploit
  • EPSS 86.75%
  • Published 05.09.2023 22:15:08
  • Last modified 21.11.2024 08:15:14

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, under certain conditions, an authenticated privileged user, can use a malicious string in the SNMP options of a Device, performing command injection and o...

Exploit
  • EPSS 0.17%
  • Published 05.09.2023 22:15:08
  • Last modified 21.11.2024 08:15:14

Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically crafted URL. The `auth_changepass...

Exploit
  • EPSS 0.45%
  • Published 05.09.2023 21:15:47
  • Last modified 21.11.2024 08:15:34

Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data...