ZeroHour

Vulnerabilities

117 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-2750
Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon

Improper Input Validation vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centreon Open Tickets modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10; 24.10;24.04.

NVD description · AI analysis pending
9.8<1%
  • centreon web
CVE-2026-2749
Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Se

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

NVD description · AI analysis pending
8.8<1%
  • centreon open tickets
CVE-2026-2751
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion.

Blind SQL Injection via unsanitized array keys in Service Dependencies deletion. Vulnerability in Centreon Centreon Web on Central Server on Linux (Service Dependencies modules) allows Blind SQL Injection.This issue affects Centreon Web on Central Server before 25.10.8, 24.10.20, 24.04.24.

NVD description · AI analysis pending
9.8<1%
  • centreon centreon web
CVE-2025-15029
+1 in the same advisory: …15026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.3, from 24.04.0 before 24.04.3.

NVD description · AI analysis pending
9.813%
  • centreon awie
CVE-2025-5965
+3 in the same advisory: …12519 …13056 …12513
OS Command Injection in Centreon Infra Monitoring backup configuration

CVE-2025-5965 is an OS command injection flaw (CWE-78) in the backup configuration of the administration setup modules in Centreon Infra Monitoring (the on-premises web interface of Centreon's IT infrastructure monitoring platform, listed under CPE as Centreon Web). A user with high privileges on the web interface can concatenate custom instructions to the backup setup, and because these parameters are not properly neutralized before being passed to the operating system, arbitrary OS commands are executed when the backup jobs run. An attacker who already holds high-privilege (admin-level) access can therefore escalate from application administration to OS-level command execution on the monitoring server, with high impact on confidentiality, integrity, and availability. Deployments running the 24.04 branch before 24.04.19, the 24.10 branch before 24.10.15, or the 25.10 branch before 25.10.2 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 28.6% (98th percentile) signals an elevated probability of exploitation within 30 days.

Do: Upgrade Centreon Infra Monitoring to 24.04.19, 24.10.15, or 25.10.2 depending on your branch. Until patched, restrict high-privilege accounts on the web interface and review configured backup parameters for unexpected or injected shell commands. Because exploitation requires admin access, audit admin accounts, and inspect backup job logs for anomalous command execution or unexpected child processes spawned during backup runs.

7.2
group max
29%
  • Centreon Infra Monitoring from 24.04.0 before 24.04.19
  • Centreon Infra Monitoring from 24.10.0 before 24.10.15
  • Centreon Infra Monitoring from 25.10.0 before 25.10.2
moderatelikely thousands to low tens of thousands of on-prem monitoring servers (order of magnitude ~10^3-10^4) running the affected branches
CVE-2025-12511
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configurat

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (DSM extenstio configuration modules) allows Stored XSS to user with elevated privileges. This issue affects Infra Monitoring: from 25.10.0 before 25.10.1, from 24.10.0 before 24.10.4, from 24.04.0 before 24.04.8.

NVD description · AI analysis pending
4.8<1%
  • centreon dynamic service management
CVE-2025-12514
+1 in the same advisory: …8460
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rul

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring - Open-tickets (Notification rules configuration parameters, Open tickets modules) allows SQL Injection to user with elevated privileges.This issue affects Infra Monitoring - Open-tickets: from 24.10.0 before 24.10.5, from 24.04.0 before 24.04.5, from 23.10.0 before 23.10.4.

NVD description · AI analysis pending
7.2
group max
<1%
  • centreon open tickets
CVE-2025-54890
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Hostgroup configuration page) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19, from 23.10.0 before 23.10.29.

NVD description · AI analysis pending
4.8<1%
  • centreon centreon web
CVE-2025-10023
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services m

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon Infra Monitoring (Services Meta-services modules) allows Stored XSS by users with elevated privileges.This issue affects Infra Monitoring: from 24.10.0 before 24.10.9, from 24.04.0 before 24.04.16, from 23.10.0 before 23.10.26.

NVD description · AI analysis pending
4.8<1%
  • centreon centreon web
CVE-2025-5946
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in th

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameters page, a user with high privilege is able to concatenate custom instructions into the poller reload command. This issue affects Infra Monitoring: from 24.10.0 before 24.10.13, from 24.04.0 before 24.04.18, from 23.10.0 before 23.10.28.

NVD description · AI analysis pending
7.2
group max
14%
  • centreon centreon web
CVE-2025-6791
+1 in the same advisory: …4650
In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB.

In the monitoring event logs page, it is possible to alter the http request to insert a reflect payload in the DB. Caused by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon web (Monitoring event logs modules) allows SQL Injection.This issue affects web: 24.10.0, 24.04.0, 23.10.0.

NVD description · AI analysis pending
8.8
group max
<1%
  • centreon centreon web
CVE-2025-4646
+3 in the same advisory: …4648 …4649 …4647
Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web:

Incorrect Authorization vulnerability in Centreon web (API Token creation form modules) allows Privilege Escalation.This issue affects web: from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

NVD description · AI analysis pending
7.2
group max
<1%
  • centreon centreon web
CVE-2025-3872
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) al

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon centreon-web (User configuration form modules) allows SQL Injection. A user with high privileges is able to become administrator by intercepting the contact form request and altering its payload. This issue affects Centreon: from 22.10.0 before 22.10.28, from 23.04.0 before 23.04.25, from 23.10.0 before 23.10.20, from 24.04.0 before 24.04.10, from 24.10.0 before 24.10.4.

NVD description · AI analysis pending
7.2<1%
  • centreon centreon web
CVE-2024-55573
+1 in the same advisory: …53923
An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24.

An issue was discovered in Centreon centreon-web 24.10.x before 24.10.3, 24.04.x before 24.04.9, 23.10.x before 23.10.19, 23.04.x before 23.04.24. A user with high privileges is able to inject SQL into the form used to create virtual metrics.

NVD description · AI analysis pending
7.21%
  • centreon centreon web
CVE-2024-39842
+1 in the same advisory: …39843
A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.

NVD description · AI analysis pending
7.2
group max
2%
  • centreon centreon
CVE-2024-32501
+4 in the same advisory: …33853 …33852 …33854 …39841
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.0

A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

NVD description · AI analysis pending
9.8
group max
19%
  • centreon centreon web
CVE-2024-5725
+1 in the same advisory: …5723
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability.

Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the initCurveList function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the apache user. Was ZDI-CAN-22683.

NVD description · AI analysis pending
8.847%
  • centreon centreon web
CVE-2023-51633
Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability.

Centreon sysName Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. User interaction is required to exploit this vulnerability. The specific flaw exists within the processing of the sysName OID in SNMP. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-20731.

NVD description · AI analysis pending
9.61%
  • centreon centreon web
CVE-2024-0637
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability.

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the updateDirectory function. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-22294.

NVD description · AI analysis pending
8.8
group max
72%
  • centreon centreon web
CVE-2022-42429
+1 in the same advisory: …42428
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon.

This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of requests to modify poller broker configuration. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-18557.

NVD description · AI analysis pending
8.876%
  • centreon centreon