CVE-2020-36947
- EPSS 0.01%
- Veröffentlicht 27.01.2026 15:23:49
- Zuletzt bearbeitet 02.02.2026 19:48:55
LibreNMS 1.46 contains an authenticated SQL injection vulnerability in the MAC accounting graph endpoint that allows remote attackers to extract database information. Attackers can exploit the vulnerability by manipulating the 'sort' parameter with c...
CVE-2025-68614
- EPSS 0%
- Veröffentlicht 22.12.2025 23:43:02
- Zuletzt bearbeitet 02.01.2026 18:23:30
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.12.0, the Alert Rule API is vulnerable to stored cross-site scripting. Alert rules can be created or updated via LibreNMS API. The alert rule name is no...
CVE-2025-65093
- EPSS 0%
- Veröffentlicht 18.11.2025 23:02:04
- Zuletzt bearbeitet 20.11.2025 16:18:22
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based blind SQL injection vulnerability was identified in the LibreNMS application at the /ajax_output.php endpoint. The hostname parame...
CVE-2025-65014
- EPSS 0%
- Veröffentlicht 18.11.2025 23:01:40
- Zuletzt bearbeitet 20.11.2025 16:17:59
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was identified in the user management functionality of the LibreNMS application. This vulnerability allows ad...
CVE-2025-65013
- EPSS 0%
- Veröffentlicht 18.11.2025 23:01:21
- Zuletzt bearbeitet 20.11.2025 16:17:47
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cross-site scripting (XSS) vulnerability was identified in the LibreNMS application at the /maps/nodeimage endpoint. The Image Name pa...
CVE-2025-62412
- EPSS 0%
- Veröffentlicht 16.10.2025 17:54:09
- Zuletzt bearbeitet 23.10.2025 12:31:34
LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitized, and can be used to inject HTML code. This vulnerability is fixed in 25.10.0.
CVE-2025-62411
- EPSS 0.01%
- Veröffentlicht 16.10.2025 17:50:28
- Zuletzt bearbeitet 23.10.2025 12:31:17
LibreNMS is a community-based GPL-licensed network monitoring system. LibreNMS <= 25.8.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Alert Transports management functionality. When an administrator creates a new Alert Transport...
CVE-2025-62365
- EPSS 0%
- Veröffentlicht 13.10.2025 21:43:49
- Zuletzt bearbeitet 20.10.2025 17:27:06
LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to 25.7.0, there is a reflected-XSS in `report_this` function in `librenms/includes/functions.php`. The `report_this` function had improper filtering (`htmlentities` fu...
CVE-2025-55296
- EPSS 0.01%
- Veröffentlicht 18.08.2025 17:27:52
- Zuletzt bearbeitet 10.09.2025 14:23:14
librenms is a community-based GPL-licensed network monitoring system. A stored Cross-Site Scripting (XSS) vulnerability exists in LibreNMS (<= 25.6.0) in the Alert Template creation feature. This allows a user with the admin role to inject malicious ...
CVE-2025-54138
- EPSS 0.03%
- Veröffentlicht 22.07.2025 21:33:59
- Zuletzt bearbeitet 05.08.2025 17:52:39
LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of network hardware and operating systems. LibreNMS versions 25.6.0 and below contain an architectural vulnerability in the ajax_form.php ...