Centreon/centreon
This hub aggregates every CVE we track for Centreon/centreon, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
27
CVEs tracked
4
Critical
13
High
0
In CISA KEV
Severity distribution
HIGH13MEDIUM10CRITICAL4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Centreon/centreon.
- CVE-2024-23119Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability8.8
- CVE-2024-23118Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability7.2
- CVE-2024-23117Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability7.2
- CVE-2024-23116Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability7.2
- CVE-2024-23115Centreon updateGroups SQL Injection Remote Code Execution Vulnerability7.2
- CVE-2024-0637Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability8.8
- CVE-2022-3827centreon Contact Groups Form formContactGroup.php sql injection6.3
- CVE-2022-40044Centreon v20.10.18 was discovered to contain a cross-site scripting (XSS) vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations. This vulnerability a...5.4
- CVE-2022-40043Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter at Configuration/Notifications/Escalations.8.8
- CVE-2020-22345/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.8.8
- CVE-2021-27676Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored X...5.4
- CVE-2021-28055An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.6.5
- CVE-2020-10945Centreon before 19.10.7 exposes Session IDs in server responses.4.3
- CVE-2020-13252Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the inclu...8.8
- CVE-2019-16405Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code Execution by an administrator who can modify Macro Expression location setti...7.2
Product normalization is registry-driven with AI assist and human review. How it works