icinga Summary
Latest vulnerabilities published by icinga
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Access Control Issue in Icinga DB Web by Icinga
CVE-2025-53840IcingaIcingadb-web2.4LOWCertificate Validation Bypass in Icinga 2 Monitoring System
CVE-2025-48057IcingaIcinga29.3CRITICALURL Manipulation Vulnerability in Icinga Web 2 by Icinga
CVE-2025-30164IcingaIcingaweb24.1MEDIUMJavaScript Injection Vulnerability in Icinga Web 2 by Icinga
CVE-2025-27609IcingaIcingaweb21.1LOWJavaScript Injection Vulnerability in Icinga Reporting by Icinga
CVE-2025-27406IcingaIcingaweb2-module-repo...7.7HIGHCross-Site Scripting Vulnerability in Icinga Web 2 by Icinga
CVE-2025-27405IcingaIcingaweb27.7HIGHArbitrary JavaScript Injection Vulnerability in Icinga Web 2 by Icinga
CVE-2025-27404IcingaIcingaweb27.7HIGHInformation Disclosure Vulnerability in Icinga Director by Icinga
CVE-2025-23203IcingaIcingaweb2-module-dire...5.5MEDIUMFlawed TLS Certificate Validation in Icinga V2 Allowing Impersonation
CVE-2024-49369IcingaEPSS 17%Icinga Addresses CSRF Vulnerability in ipl/web
CVE-2024-41811IcingaIpl-web3.9LOWIcinga Director Vulnerable to Cross-Site Request Forgery (CSRF) Attacks
CVE-2024-24820IcingaIcingaweb2-module-dire...8.3HIGHCross-Site Request Forgery Vulnerability Affects Icinga Web 2 Versions
CVE-2024-24819IcingaIcingaweb2-module-incu...5.3MEDIUMicingaweb2-module-jira template and field configuration are susceptible to CSRF
CVE-2023-30607IcingaIcingaweb2-module-jira5MEDIUMDisclosure of hosts and related data, linked to decommissioned services in Icinga Web 2
CVE-2022-24714IcingaIcingaweb25.3MEDIUMArbitrary code execution for authenticated users in Icinga Web 2
CVE-2022-24715IcingaIcingaweb2πΎπ‘EPSS 72%8.5HIGHPath traversal in Icinga Web 2
CVE-2022-24716IcingaIcingaweb2πΎπ‘EPSS 93%7.5HIGHMissing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer
CVE-2021-37698IcingaIcinga27.5HIGHPasswords used to access external services inadvertently exposed through API
CVE-2021-32743IcingaIcinga28.8HIGHResults of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities
CVE-2021-32739IcingaIcinga28.8HIGHPossible path traversal by use of the `doc` module
CVE-2021-32746IcingaIcingaweb25.3MEDIUMCustom variable protection and blacklists can be circumvented
CVE-2021-32747IcingaIcingaweb25.3MEDIUMCertificate Renewal Bypass in Icinga 2 by Icinga
CVE-2020-29663IcingaIcinga9.1CRITICALDirectory Traversal Vulnerability in Icinga Web2 by Icinga
CVE-2020-24368IcingaIcinga Web 27.5HIGHUnauthorized File Permission Changes in Icinga2 by Icinga
CVE-2020-14004IcingaIcinga7.8HIGHCross-Site Request Forgery in Icinga Web 2 Affects Monitoring Module
CVE-2018-18246IcingaIcinga Web 26.5MEDIUM