Vulnerabilities > Icinga > Low

DATE CVE VULNERABILITY TITLE RISK
2021-07-12 CVE-2021-32746 Path Traversal vulnerability in Icinga
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface.
network
icinga CWE-22
3.5
2018-12-17 CVE-2018-18247 Cross-site Scripting vulnerability in Icinga web 2
Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
network
icinga CWE-79
3.5
2011-06-14 CVE-2011-2477 Cross-Site Scripting vulnerability in Icinga
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179.
network
high complexity
icinga CWE-79
2.6