CVE-2024-34340
- EPSS 0.84%
- Veröffentlicht 14.05.2024 15:38:39
- Zuletzt bearbeitet 04.11.2025 17:15:53
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verify...
CVE-2024-31459
- EPSS 2.18%
- Veröffentlicht 14.05.2024 15:25:26
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. The...
CVE-2024-31460
- EPSS 1.69%
- Veröffentlicht 14.05.2024 15:25:26
- Zuletzt bearbeitet 04.11.2025 17:15:51
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules.php` is not thoroughly checked and is used to concatenate the SQL statement in `create_all_header_node...
- EPSS 6.02%
- Veröffentlicht 14.05.2024 15:25:25
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `form_save()` function in `graph_template_inputs.php` is not thoroughly checked and is used to concatenate the SQL statement ...
CVE-2024-31445
- EPSS 39.47%
- Veröffentlicht 14.05.2024 15:25:21
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users to exploit these SQL inject...
CVE-2024-31443
- EPSS 0.49%
- Veröffentlicht 14.05.2024 15:25:20
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to 1.2.27, some of the data stored in `form_save()` function in `data_queries.php` is not thoroughly checked and is used to concatenate the HTML statement in `grow_right_p...
CVE-2024-31444
- EPSS 9.4%
- Veröffentlicht 14.05.2024 15:25:20
- Zuletzt bearbeitet 04.11.2025 17:15:50
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, some of the data stored in `automation_tree_rules_form_save()` function in `automation_tree_rules.php` is not thoroughly checked and is used to concaten...
CVE-2024-29894
- EPSS 0.16%
- Veröffentlicht 14.05.2024 15:17:14
- Zuletzt bearbeitet 18.12.2024 21:10:38
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/func...
CVE-2024-27834
- EPSS 0.01%
- Veröffentlicht 14.05.2024 15:13:06
- Zuletzt bearbeitet 04.11.2025 18:16:14
The issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, tvOS 17.5, Safari 17.5, watchOS 10.5, macOS Sonoma 14.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
CVE-2024-27400
- EPSS 0.01%
- Veröffentlicht 14.05.2024 15:12:29
- Zuletzt bearbeitet 23.12.2025 19:05:59
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that af...