VYPR
Vendor

Centreon

Products
14
CVEs
139
Across products
228
Status
Private

Products

14

Recent CVEs

139
View all 139 CVEs →
  • CVE-2025-15029CriJan 5, 2026
    risk 0.65cvss 9.8epss 0.11

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0…

  • CVE-2024-32501CriAug 23, 2024
    risk 0.65cvss 9.8epss 0.19

    A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2026-2749CriFeb 27, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

  • CVE-2025-15026CriJan 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before…

  • CVE-2022-41142HigJan 26, 2023
    risk 0.64cvss 8.8epss 0.86

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to configure poller resources. The issue results from the…

  • CVE-2018-21025CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.03

    In Centreon VM through 19.04.3, centreon-backup.pl allows attackers to become root via a crafted script, due to incorrect rights of sourced configuration files.

  • CVE-2022-42429HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.78

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42427HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the contact groups configuration page. The issue results from the lack of proper…

  • CVE-2022-42425HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2022-42424HigMar 29, 2023
    risk 0.63cvss 8.8epss 0.76

    This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results…

  • CVE-2023-51633CriMay 3, 2024
    risk 0.62cvss 9.6epss 0.01

    Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2024-5723HigAug 21, 2024
    risk 0.60cvss 8.8epss 0.41

    Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within…

  • CVE-2021-37557HigAug 3, 2021
    risk 0.60cvss 8.8epss 0.29

    A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-privileged) attackers to execute arbitrary SQL commands via the include/views/graphs/generateGraphs/generateImage.php index parameter.

  • CVE-2026-2750CriFeb 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

  • CVE-2024-55573CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.

  • CVE-2024-53923CriJan 23, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in Centreon Web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to achieve SQL injection in the form to upload media.

  • CVE-2024-33854CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33853CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2024-33852CriAug 23, 2024
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

  • CVE-2019-19487HigMar 20, 2020
    risk 0.58cvss 8.8epss 0.05

    Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.