Vulnerabilities > Cacti > Cacti > 1.2.19
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-05 | CVE-2023-39366 | Cross-site Scripting vulnerability in multiple products Cacti is an open source operational monitoring and fault management framework. | 4.8 |
2023-09-05 | CVE-2023-39510 | Cross-site Scripting vulnerability in multiple products Cacti is an open source operational monitoring and fault management framework. | 4.8 |
2023-09-05 | CVE-2023-39512 | Cross-site Scripting vulnerability in multiple products Cacti is an open source operational monitoring and fault management framework. | 4.8 |
2023-09-05 | CVE-2023-39513 | Cross-site Scripting vulnerability in multiple products Cacti is an open source operational monitoring and fault management framework. | 5.4 |
2023-09-05 | CVE-2023-39514 | Cross-site Scripting vulnerability in multiple products Cacti is an open source operational monitoring and fault management framework. | 5.4 |
2023-09-05 | CVE-2023-39515 | Cross-site Scripting vulnerability in multiple products Cacti is an open source operational monitoring and fault management framework. | 4.8 |
2023-08-22 | CVE-2022-48538 | Incorrect Authorization vulnerability in Cacti 1.2.19 In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password. | 5.3 |
2022-12-05 | CVE-2022-46169 | Incorrect Authorization vulnerability in Cacti Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. | 9.8 |
2022-03-03 | CVE-2022-0730 | Improper Authentication vulnerability in multiple products Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. | 9.8 |