VYPR

Centreon

by Centreon

Source repositories

CVEs (130)

  • CVE-2025-15029CriJan 5, 2026
    risk 0.65cvss 9.8epss 0.11

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0…

  • CVE-2024-32501CriAug 23, 2024
    risk 0.65cvss 9.8epss 0.19

    A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2025-15026CriJan 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before…

  • CVE-2022-41142HigJan 26, 2023
    risk 0.64cvss 8.8epss 0.86

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the…

  • CVE-2022-42429HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.78

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42427HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper…

  • CVE-2022-42425HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42424HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2023-51633CriMay 3, 2024
    risk 0.62cvss 9.6epss 0.01

    Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-5723HigAug 21, 2024
    risk 0.60cvss 8.8epss 0.41

    Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2021-37557HigAug 3, 2021
    risk 0.60cvss 8.8epss 0.29

    A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

  • CVE-2024-55573CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.

  • CVE-2024-53923CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.

  • CVE-2024-33854CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33853CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33852CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2019-19487HigMar 20, 2020
    risk 0.58cvss 8.8epss 0.05

    Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.

  • CVE-2020-9463HigFeb 28, 2020
    risk 0.58cvss 8.8epss 0.04

    Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.

  • CVE-2025-6791HigAug 22, 2025
    risk 0.57cvss 8.8epss 0.00

    In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules)…

  • CVE-2022-42428HigMar 29, 2023
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

Page 1 of 7