Icingaweb2
Icinga · 9 CVEs
CVE-2025-30164
MEDIUM
Icinga Web 2 has open redirect on login page
Mar 26, 2025
CVE-2025-27609
LOW
Icinga Web 2 Vulnerable to Reflected XSS
Mar 26, 2025
CVE-2025-27405
HIGH
Icinga Web 2 has XSS in embedded content
Mar 26, 2025
CVE-2025-27404
HIGH
Icinga Web 2 DOM-based XSS vulnerability
Mar 26, 2025
CVE-2022-24714
MEDIUM
Disclosure of hosts and related data, linked to decommissioned services in Icinga Web 2
Mar 8, 2022
CVE-2022-24716
HIGH
Path traversal in Icinga Web 2
Mar 8, 2022
CVE-2022-24715
HIGH
Arbitrary code execution for authenticated users in Icinga Web 2
Mar 8, 2022
CVE-2021-32747
MEDIUM
Custom variable protection and blacklists can be circumvented
Jul 12, 2021
CVE-2021-32746
MEDIUM
Possible path traversal by use of the `doc` module
Jul 12, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-30164 | Icinga Web 2 has open redirect on login page | MEDIUM | 0.26% | Mar 26, 2025 |
| CVE-2025-27609 | Icinga Web 2 Vulnerable to Reflected XSS | LOW | 0.25% | Mar 26, 2025 |
| CVE-2025-27405 | Icinga Web 2 has XSS in embedded content | HIGH | 0.33% | Mar 26, 2025 |
| CVE-2025-27404 | Icinga Web 2 DOM-based XSS vulnerability | HIGH | 0.60% | Mar 26, 2025 |
| CVE-2022-24714 | Disclosure of hosts and related data, linked to decommissioned services in Icinga Web 2 | MEDIUM | 1.23% | Mar 8, 2022 |
| CVE-2022-24716 | Path traversal in Icinga Web 2 | HIGH | 89.38% | Mar 8, 2022 |
| CVE-2022-24715 | Arbitrary code execution for authenticated users in Icinga Web 2 | HIGH | 14.67% | Mar 8, 2022 |
| CVE-2021-32747 | Custom variable protection and blacklists can be circumvented | MEDIUM | 1.38% | Jul 12, 2021 |
| CVE-2021-32746 | Possible path traversal by use of the `doc` module | MEDIUM | 1.31% | Jul 12, 2021 |
Showing 1 to 9 of 9 CVEs