Products: 2
    Vulnerabilities: 16
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2013-3935

    Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.

    Last Modified: Nov 21, 2024
    Published: Jan 02, 2020

    CVE-2013-3936

    Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.

    Last Modified: Nov 21, 2024
    Published: Jan 02, 2020

    CVE-2018-16146

    The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurable events. The value parameter is not properly sanitized, leading to arbitrary command injection with the privileges of the nagios user account.

    Last Modified: Nov 21, 2024
    Published: Sep 05, 2018

    CVE-2018-16147

    The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.

    Last Modified: Nov 21, 2024
    Published: Sep 05, 2018

    CVE-2018-16144

    The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password parameter.

    Last Modified: Nov 21, 2024
    Published: Sep 05, 2018
    Items Per Page