Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
librenms librenms vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2019-10671
An issue exists in LibreNMS up to and including 1.47. It does not parameterize all user supplied input within database queries, resulting in SQL injection. An authenticated attacker can subvert these database queries to extract or manipulate data, as demonstrated by the graph.php...
Librenms Librenms
8.8
CVSSv3
CVE-2019-12463
An issue exists in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.php and includes/html/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_e...
Librenms Librenms
8.1
CVSSv3
CVE-2019-12465
An issue exists in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where the term parameter is used insecurely in a database query for showing columns of a table, as demonstrated by an ajax_rulesuggest.php?debug=1&term= request.
Librenms Librenms
5.4
CVSSv3
CVE-2022-3231
Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms before 22.9.0.
Librenms Librenms
5.4
CVSSv3
CVE-2022-0575
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms before 22.2.0.
Librenms Librenms
6.1
CVSSv3
CVE-2022-0576
Cross-site Scripting (XSS) - Generic in Packagist librenms/librenms before 22.1.0.
Librenms Librenms
8.8
CVSSv3
CVE-2022-0580
Incorrect Authorization in Packagist librenms/librenms before 22.2.0.
Librenms Librenms
6.5
CVSSv3
CVE-2022-0587
Improper Authorization in Packagist librenms/librenms before 22.2.0.
Librenms Librenms
6.5
CVSSv3
CVE-2022-0588
Missing Authorization in Packagist librenms/librenms before 22.2.0.
Librenms Librenms
5.4
CVSSv3
CVE-2022-0589
Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms before 22.1.0.
Librenms Librenms
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »