CVE-2026-55182
- EPSS 1.13%
- Veröffentlicht 26.08.2026 21:50:04
- Zuletzt bearbeitet 09.09.2026 21:09:13
LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped be...
CVE-2026-45694
- EPSS 0.15%
- Veröffentlicht 26.08.2026 21:42:01
- Zuletzt bearbeitet 09.09.2026 21:09:13
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the pag...
CVE-2026-80214
- EPSS 0.42%
- Veröffentlicht 26.08.2026 02:11:01
- Zuletzt bearbeitet 09.09.2026 15:52:04
LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.
CVE-2020-15874
- EPSS 0.56%
- Veröffentlicht 26.08.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:52:51
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands through a command injection in the /graph.php API endpoint.
CVE-2020-15876
- EPSS 0.23%
- Veröffentlicht 26.08.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:52:51
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the sort parameter in the /ajax_table.php API endpoint. This affects ad...
CVE-2020-15878
- EPSS 0.28%
- Veröffentlicht 26.08.2026 00:00:00
- Zuletzt bearbeitet 03.09.2026 17:52:51
An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the address parameter in the /ajax_table.php API endpoint.
CVE-2024-51092
- EPSS 7.18%
- Veröffentlicht 08.05.2026 00:00:00
- Zuletzt bearbeitet 12.05.2026 13:50:21
LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's initRrdDirectory().
CVE-2026-30480
- EPSS 0.27%
- Veröffentlicht 14.04.2026 00:00:00
- Zuletzt bearbeitet 17.04.2026 15:24:57
A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parame...
CVE-2026-6204
- EPSS 7.53%
- Veröffentlicht 13.04.2026 10:56:16
- Zuletzt bearbeitet 22.04.2026 19:47:46
LibreNMS versions before 26.3.0 are affected by an authenticated remote code execution vulnerability by abusing the Binary Locations config and the Netcommand feature. Successful exploitation requires administrative privileges. Exploitation could res...
CVE-2026-2728
- EPSS 0.23%
- Veröffentlicht 13.04.2026 10:39:54
- Zuletzt bearbeitet 22.04.2026 19:46:01
LibreNMS versions before 26.3.0 are affected by an authenticated Cross-site Scripting vulnerability on the showconfig page. Successful exploitation requires administrative privileges. Exploitation could result in XSS attacks being performed against o...