ZeroHour

Vulnerabilities

38 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-67835
+2 in the same advisory: …67833 …67834
Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.

Paessler PRTG Network Monitor before 25.4.114 allows Denial-of-Service (DoS) by an authenticated attacker via the Notification Contacts functionality.

NVD description · AI analysis pending
6.5
group max
<1%
  • paessler prtg network monitor
CVE-2024-12833
Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability.

Paessler PRTG Network Monitor SNMP Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. Some user interaction on the part of an administrator is required to exploit this vulnerability. The specific flaw exists within the PRTG Network Monitor web interface. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-23371.

NVD description · AI analysis pending
6.1<1%
  • paessler prtg network monitor
CVE-2023-51630
Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability.

Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the web console. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of an arbitrary script. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-21182.

NVD description · AI analysis pending
6.12%
  • paessler prtg network monitor
CVE-2023-31452
A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with t

A cross-site request forgery (CSRF) token bypass was identified in PRTG 23.2.84.1566 and earlier versions that allows remote attackers to perform actions with the permissions of a victim user, provided the victim user has an active session and is induced to trigger the malicious request. This could force PRTG to execute different actions, such as creating new users. The severity of this vulnerability is high and received a score of 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

NVD description · AI analysis pending
8.8
group max
<1%
  • paessler prtg network monitor
CVE-2022-35739
PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style ta

PRTG Network Monitor through 22.2.77.2204 does not prevent custom input for a device’s icon, which can be modified to insert arbitrary content into the style tag for that device. When the device page loads, the arbitrary Cascading Style Sheets (CSS) data is inserted into the style tag, loading malicious content. Due to PRTG Network Monitor preventing “characters, and from modern browsers disabling JavaScript support in style tags, this vulnerability could not be escalated into a Cross-Site Scripting vulnerability.

NVD description · AI analysis pending
5.3<1% PoC
  • paessler prtg network monitor
CVE-2021-29643
PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.

PRTG Network Monitor before 21.3.69.1333 allows stored XSS via an unsanitized string imported from a User Object in a connected Active Directory instance.

NVD description · AI analysis pending
5.4<1% PoC
  • paessler prtg network monitor
CVE-2021-34547
PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.

PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.

NVD description · AI analysis pending
4.3<1% PoC
  • paessler prtg network monitor
CVE-2021-27220
An issue was discovered in PRTG Network Monitor before 21.1.66.1623.

An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepared context paths, an attacker is able to verify the existence of certain files on the filesystem of the PRTG's Web server.

NVD description · AI analysis pending
5.32%
  • paessler prtg network monitor
CVE-2020-14073
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties.

XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen to insert JavaScript code. This can be exploited against any user with View Maps or Edit Maps access.

NVD description · AI analysis pending
5.43% PoC ×2
  • paessler prtg network monitor
CVE-2020-11547
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, mem

PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version, and internal statistics) via an HTTP request, as demonstrated by type=probes to login.htm or index.htm.

NVD description · AI analysis pending
5.352%
  • paessler prtg network monitor
CVE-2020-10374
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the

A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.

NVD description · AI analysis pending
9.85%
  • paessler prtg network monitor
CVE-2019-11074
A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations

A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attackers to place files in arbitrary locations with SYSTEM privileges (although not controlling the contents of such files) due to insufficient sanitisation when passing arguments to the phantomjs.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Full Web Page Sensor and set specific settings when executing the sensor.

NVD description · AI analysis pending
7.25% PoC
  • paessler prtg network monitor
CVE-2019-11073
A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization

A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execute code due to insufficient sanitization when passing arguments to the HttpTransactionSensor.exe binary. In order to exploit the vulnerability, remote authenticated administrators need to create a new HTTP Transaction Sensor and set specific settings when the sensor is executed.

NVD description · AI analysis pending
7.26% PoC
  • paessler prtg network monitor
CVE-2019-19119
An issue was discovered in PRTG 7.x through 19.4.53.

An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.

NVD description · AI analysis pending
5.5<1%
  • paessler prtg network monitor
CVE-2019-9207
+1 in the same advisory: …9206
PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter.

PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued.

NVD description · AI analysis pending
6.11%
  • paessler prtg network monitor
CVE-2018-14683
PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.

PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.

NVD description · AI analysis pending
6.1<1%
  • paessler prtg network monitor
CVE-2018-19410
+1 in the same advisory: …19411
Unauthenticated LFI in Paessler PRTG Enables Admin Account Creation

CVE-2018-19410 is a local file inclusion (LFI) flaw in the PRTG Network Monitor web login page (/public/login.htm) where an attacker can override the 'include' directive via a crafted HTTP request. By directing the include to /api/addusers and supplying the 'id' and 'users' parameters, a remote, unauthenticated attacker triggers that API and creates a new user with read-write privileges, including full administrator. Effectively, this gives an unauthenticated remote attacker persistent, privileged access to the monitoring server's console, with visibility into monitored infrastructure and the ability to alter monitoring configuration. Any PRTG Network Monitor deployment running a version prior to 18.2.40.1683 is affected, with risk concentrated on instances whose web interface is reachable by attackers (internet-exposed consoles, or consoles reachable from compromised internal networks). The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-04 with a federal patch deadline of 2025-02-25, and its EPSS score of 97.9% (100th percentile) indicates near-certain likelihood of exploitation within 30 days, though no public proof-of-concept is known.

Do: Upgrade PRTG Network Monitor to version 18.2.40.1683 or later (current releases include the fix; CISA's required action is to apply vendor mitigations or discontinue use). Until patched, restrict access to the PRTG web console (e.g., firewall it to trusted management networks and avoid internet exposure). Review the web server logs for unauthenticated requests to /public/login.htm with manipulated 'include' parameters or calls to /api/addusers, and audit existing PRTG user accounts for unauthorized administrator accounts created via this flaw.

9.8
group max
98% KEV
  • paessler prtg network monitor before 18.2.40.1683
largelikely on the order of hundreds of thousands of installations, with at least tens of thousands of web consoles potentially reachable (estimate; no count in…
CVE-2018-19204
+1 in the same advisory: …19203
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with syst

PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When creating an HTTP Advanced Sensor, the user's input in the POST parameter 'proxyport_' is mishandled. The attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe to store arbitrary data in an arbitrary place on the file system. For example, the attacker can create an executable file in the \Custom Sensors\EXE directory and execute it by creating EXE/Script Sensor.

NVD description · AI analysis pending
8.8
group max
5%
  • paessler prtg network monitor
CVE-2018-9276
Authenticated OS Command Injection in Paessler PRTG Network Monitor < 18.2.39

Paessler PRTG Network Monitor versions before 18.2.39 contain an OS command injection flaw (CWE-78) in the PRTG System Administrator web console. An attacker with administrative access to that console can trigger arbitrary command execution on both the PRTG server and on monitored devices by sending malformed parameters in sensor or notification management scenarios, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2, high privileges required, no user interaction). Any organization running PRTG Network Monitor older than 18.2.39 is affected, although exploitation requires valid administrative access to the console. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-02-04, confirming active in-the-wild exploitation, with public proof-of-concept references (Exploit-DB 46527 and two PacketStorm entries) and an EPSS probability of 87% of exploitation within 30 days. Defenders running unpatched PRTG instances, especially consoles reachable from the internet, should treat this as actively targeted.

Do: Upgrade PRTG Network Monitor to 18.2.39 or later (any current release includes the fix); per CISA's KEV entry, apply vendor mitigations or discontinue use of unpatched versions by the February 25, 2025 deadline. Inventory PRTG servers — particularly consoles exposed to the internet — restrict System Administrator console access to trusted users and networks, and audit sensor and notification configurations and logs for tampering or unexpected command execution.

7.287% KEV PoC ×3
  • paessler prtg network monitor All versions before 18.2.39 (fixed in 18.2.39)
largeTens of thousands of on-premises installations / hundreds of thousands of users historically affected (estimate; no authoritative count in the data)
CVE-2018-10253
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.

Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.

NVD description · AI analysis pending
7.57%
  • paessler prtg network monitor
CVE-2017-15917
In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.

In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.

NVD description · AI analysis pending
6.5<1%
  • paessler prtg network monitor
CVE-2017-15651
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of

PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.

NVD description · AI analysis pending
6.71%
  • paessler prtg network monitor
CVE-2017-15360
PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HT

PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HTML encoded script.

NVD description · AI analysis pending
5.4<1% PoC
  • paessler prtg network monitor
CVE-2017-15009
+1 in the same advisory: …15008
PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.

PRTG Network Monitor version 17.3.33.2830 is vulnerable to reflected Cross-Site Scripting on error.htm (the error page), via the errormsg parameter.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • paessler prtg network monitor
CVE-2017-12879
Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticate

Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML.

NVD description · AI analysis pending
5.41%
  • paessler prtg network monitor
CVE-2017-9816
Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via

Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

NVD description · AI analysis pending
6.1<1%
  • paessler prtg network monitor
CVE-2016-5078
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.

Paessler PRTG before 16.2.24.4045 has XSS via SNMP.

NVD description · AI analysis pending
6.1<1%
  • paessler prtg network monitor