Vulnerabilities > Icinga > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-03-08 CVE-2022-24714 Unspecified vulnerability in Icinga web 2
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface.
network
low complexity
icinga
5.3
2021-07-12 CVE-2021-32746 Path Traversal vulnerability in Icinga
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface.
network
high complexity
icinga CWE-22
5.3
2021-07-12 CVE-2021-32747 Information Exposure vulnerability in Icinga
Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface.
network
low complexity
icinga CWE-200
6.5
2018-12-17 CVE-2018-18248 Cross-site Scripting vulnerability in Icinga web 2 2.6.1
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.
network
low complexity
icinga CWE-79
6.1
2018-12-17 CVE-2018-18247 Cross-site Scripting vulnerability in Icinga web 2
Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
network
low complexity
icinga CWE-79
5.4
2018-12-17 CVE-2018-18246 Cross-Site Request Forgery (CSRF) vulnerability in Icinga web 2
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
network
low complexity
icinga CWE-352
6.5
2018-02-27 CVE-2018-6534 NULL Pointer Dereference vulnerability in Icinga
An issue was discovered in Icinga 2.x through 2.8.1.
network
low complexity
icinga CWE-476
6.5
2018-02-02 CVE-2018-6536 Incorrect Permission Assignment for Critical Resource vulnerability in Icinga
An issue was discovered in Icinga 2.x through 2.8.1.
local
low complexity
icinga CWE-732
5.5
2017-03-27 CVE-2015-8010 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.
network
low complexity
icinga opensuse-project opensuse CWE-79
6.1