Where
-Infinity
0

OpenNMS MeridianOpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only

Risk 22
Severity
4.3
First published (updated )

OpenNMS Opennms MeridianOpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes

Risk 34
Severity
5.4
First published (updated )

OpenNMS MeridianSQLi in OpenNMS Horizon and Meridian

Risk 28
Severity
6.9
EPSS
0.03%
First published (updated )

maven/org.opennms:opennms-webappCross-site scripting in bootstrap.jsp

Risk 38
Severity
6.1
First published (updated )

OpenNMS HorizonAuthenticated XXE Injection Via The File Editor

Risk 73
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

maven/org.opennms:opennms-webapp-restROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN

Risk 76
Severity
8
First published (updated )

OpenNMS MeridianDisable BeanShell Interpreter Remote Server Mode

Risk 82
Severity
8.8
First published (updated )

OpenNMS MeridianReflected XSS in multiple JSP files in opennms/opennms

Risk 51
Severity
6.7
First published (updated )

OpenNMS MeridianStored XSS in multiple JSP files in opennms/opennms

Risk 51
Severity
6.7
First published (updated )

OpenNMS MeridianROLE_REST can be used to escalate to ROLE_ADMIN via /rest/users

Risk 62
Severity
8.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenNMS MeridianAn XML External Entity injection vulnerability

Risk 66
Severity
8.8
First published (updated )

OpenNMS MeridianForm Can Be Manipulated with Cross-Site Request Forgery (CSRF)

Risk 57
Severity
8.1
First published (updated )

OpenNMS HorizonPlaintext Password Present in the Web logs

Risk 39
Severity
6.8
First published (updated )

OpenNMS HorizonMultiple stored and reflected Cross-site Scripting in webapp

Risk 50
Severity
6.7
First published (updated )

OpenNMS HorizonStealing Cookies using Reflected XSS via graph results

Risk 50
Severity
6.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenNMS HorizonCross-site scripting in outage/list.htm

Risk 38
Severity
6.1
First published (updated )

OpenNMS HorizonUnauthenticated, stored XSS in display of alarm reduction-key

Risk 50
Severity
6.7
First published (updated )

OpenNMS OpenNMSOpenNMS Stored XSS via SNMP Trap Alerts

Risk 47
Severity
7.1
First published (updated )

OpenNMS MeridianXSS

Risk 34
Severity
5.4
First published (updated )

OpenNMS MeridianXSS

Risk 34
Severity
5.4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenNMS MeridianXSS

Risk 34
Severity
5.4
First published (updated )

OpenNMS MeridianXSS

Risk 29
Severity
4.8
First published (updated )

OpenNMS MeridianCSRF

Risk 77
Severity
8.8
First published (updated )

OpenNMS MeridianXSS

Risk 29
Severity
4.8
First published (updated )

OpenNMS MeridianCSRF

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OpenNMS MeridianOpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5,…

Risk 80
Severity
8.8
First published (updated )

OpenNMS OpenNMSJunos Space: OpenNMS is accessible via port 9443

Risk 86
Severity
9.8
First published (updated )

OpenNMS Opennms MeridianAn issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 bef…

Risk 80
Severity
8.8
First published (updated )

OpenNMS MeridianSQL Injection

Risk 60
Severity
8.1
First published (updated )

OpenNMS OpenNMSOpenNMS Stored XSS via SNMP Agent Data

Risk 47
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203