Vulnerabilidades em librenms

88 resultados
Análise Vexday

O LibreNMS acumula 74 CVEs catalogadas, sem nenhuma confirmada em exploração ativa no catálogo CISA KEV — taxa abaixo da média geral do catálogo. Ainda assim, o cenário merece atenção: a CVE mais perigosa identificada, CVE-2022-3562, apresenta EPSS de 0,9422, indicando altíssima probabilidade estatística de exploração, e há 2 vulnerabilidades com PoC pública disponível, o que reduz a barreira técnica para atacantes. A falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora frequentemente subestimado, pode ser encadeado com outras fraquezas para escalada de impacto em aplicações de monitoramento de rede com acesso privilegiado. Equipes que mantêm instâncias do LibreNMS devem priorizar a remediação da CVE-2022-3562 e revisar exposições relacionadas a XSS, especialmente em ambientes acessíveis externamente.

CVE-2025-65093MEDIUMLibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpointEPSS 3.7%CVE-2026-86426CRITICALLibreNMS before 26.8.0 Authentication Bypass via API Token Type ConfusionEPSS 2.1%CVE-2026-84194HIGHLibreNMS 23.10.0 before 26.4.0 OS Command Injection via HostnameEPSS 1.4%CVE-2025-23199MEDIUMStored XSS-LibreNMS-Ports in librenmsEPSS 1.3%CVE-2022-0580HIGHIncorrect Authorization in librenms/librenmsEPSS 1.2%CVE-2026-55182HIGHLibreNMS: Remote Code Execution by Signal Alert Transportation ModuleEPSS 1.1%CVE-2025-54138HIGHLibreNMS has Authenticated Local File Inclusion in ajax_form.php that Allows RCEEPSS 1.1%CVE-2022-0588HIGHMissing Authorization in librenms/librenmsEPSS 1.1%CVE-2022-0587HIGHImproper Authorization in librenms/librenmsEPSS 1.0%CVE-2022-0576MEDIUMCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 1.0%CVE-2022-3525CRITICALDeserialization of Untrusted Data in librenms/librenmsEPSS 0.9%CVE-2022-0575MEDIUMCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 0.8%CVE-2022-0589MEDIUMCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 0.8%CVE-2023-48294MEDIUMBroken Access control on Graphs Feature in LibreNMSEPSS 0.7%CVE-2023-4980HIGHCross-site Scripting (XSS) - Generic in librenms/librenmsEPSS 0.7%CVE-2023-4979HIGHCross-site Scripting (XSS) - Reflected in librenms/librenmsEPSS 0.7%CVE-2022-3231MEDIUMCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 0.7%CVE-2023-4978CRITICALCross-site Scripting (XSS) - DOM in librenms/librenmsEPSS 0.7%CVE-2023-4981HIGHCross-site Scripting (XSS) - DOM in librenms/librenmsEPSS 0.7%CVE-2023-4982CRITICALCross-site Scripting (XSS) - Stored in librenms/librenmsEPSS 0.7%