Where
-Infinity
0

CactiCacti: Session Fixation via missing session_regenerate_id() after login

Risk 34
Severity
5.4
First published (updated )

Cacti CactiCacti has a SQL Injection vulnerability when using tree rules through Automation API

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )

Cacti CactiCacti allows Arbitrary File Creation leading to RCE

Risk 56
Severity
8.8
EPSS
0.04%
First published (updated )

Cacti CactiCacti has Authenticated RCE via multi-line SNMP responses

Risk 54
Severity
9.1
EPSS
0.04%
First published (updated )

Cacti CactiCacti has a SQL Injection vulnerability when request automation devices

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Cacti CactiCacti has a SQL Injection vulnerability when view host template

Risk 79
Severity
8.8
First published (updated )

Cacti CactiCacti has a Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path

Risk 48
Severity
6
First published (updated )

debian/cactiCacti RCE vulnerability by file include in lib/plugin.php

Risk 65
Severity
8.1
First published (updated )

debian/cactiSQL Injection vulnerability in automation_get_new_graphs_sql

Risk 79
Severity
8.8
First published (updated )

debian/cactiCacti Cross-site Scripting vulnerability when using JavaScript based messaging API

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Cacti CactiCacti Cross-site Scripting vulnerability when managing trees

Risk 62
Severity
7.6
First published (updated )

Cacti CactiSQL Injection vulnerability when managing SNMP Notification Receivers

Risk 79
Severity
8.8
First published (updated )

Cacti CactiCross-Site Scripting vulnerability when Import xml template file

Risk 38
Severity
6.1
First published (updated )

Cacti CactiSQL Injection

Risk 38
Severity
6.5
First published (updated )

Cacti CactiCacti graph_view SQL Injection Authentication Bypass Vulnerability

Risk 79
Severity
8.8
First published (updated )
Advisory
ZDI-23-1500
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Cacti CactiZDI-23-1500: Cacti graph_view SQL Injection Authentication Bypass Vulnerability

Risk 79
Severity
8.8
First published (updated )

Cacti CactiCacti link Local File Inclusion Remote Code Execution Vulnerability

Risk 61
Severity
6.6
First published (updated )
Advisory
ZDI-23-1499

Cacti CactiZDI-23-1499: Cacti link Local File Inclusion Remote Code Execution Vulnerability

Risk 61
Severity
6.6
First published (updated )

fedoraproject fedoraStored Cross-Site-Scripting on reports_admin.php device name in Cacti

Risk 45
Severity
6.1
First published (updated )

fedoraproject fedoraInsecure Deserialization in Cacti

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CactiCacti Privilege Escalation

Risk 69
Severity
7.8
First published (updated )

fedoraproject fedoraAuthenticated command injection in SNMP options of a Device

Risk 80
Severity
7.2
First published (updated )

fedoraproject fedoraOpen redirect in change password functionality in Cacti

Risk 34
Severity
5.4
First published (updated )

fedoraproject fedoraStored Cross-Site-Scripting on data_sources.php debug html-block in Cacti

Risk 45
Severity
6.1
First published (updated )

CactiCacti link Local File Inclusion Remote Code Execution Vulnerability

Risk 81
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

fedoraproject fedoraA Defect in sql_save() Causes Multiple SQL Injection Vulnerabilities in Cacti

Risk 79
Severity
8.8
First published (updated )

fedoraproject fedoraAuthenticated SQL injection vulnerability in reports_user.php in Cacti

Risk 79
Severity
8.8
First published (updated )

fedoraproject fedoraAuthenticated SQL injection vulnerability in graphs.php in Cacti

Risk 79
Severity
8.8
First published (updated )

fedoraproject fedoraReflected Cross-site Scripting in graphs_new.php in Cacti

Risk 38
Severity
6.1
First published (updated )

Fedoraproject FedoraStored Cross-site Scripting in data_sources.php through Device-Name in 'select' input in Cacti

Risk 55
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203