Paessler

Prtg

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 24.09.2026 10:57:54
  • Zuletzt bearbeitet 24.09.2026 20:43:32

PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the ...

  • EPSS 0.55%
  • Veröffentlicht 24.09.2026 10:05:06
  • Zuletzt bearbeitet 24.09.2026 20:43:32

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 \"Forbidden P...

  • EPSS 0.23%
  • Veröffentlicht 14.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 20:00:03

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

  • EPSS 0.21%
  • Veröffentlicht 14.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 19:56:19

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

  • EPSS 0.66%
  • Veröffentlicht 14.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 19:56:19

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

  • EPSS 0.23%
  • Veröffentlicht 14.01.2026 00:00:00
  • Zuletzt bearbeitet 20.01.2026 15:26:00

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the tag parameter.

  • EPSS 0.23%
  • Veröffentlicht 14.01.2026 00:00:00
  • Zuletzt bearbeitet 20.01.2026 15:26:23

Paessler PRTG Network Monitor before 25.4.114 allows XSS by an unauthenticated attacker via the filter parameter.

  • EPSS 0.36%
  • Veröffentlicht 14.01.2026 00:00:00
  • Zuletzt bearbeitet 20.01.2026 15:26:45

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.