vciy

CVEs we hold for Icinga

Records whose assigning authority named Icinga as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-61552Icinga 2 DSL Injection via Unescaped Import Template NameIcinga icinga2
CVE-2026-61551Icinga 2: Stack overflow via deeply nested JSON objectsIcinga icinga2
CVE-2026-61550Icinga 2: Improper access control for JSON-RPC update certificate messagesIcinga icinga2
CVE-2026-42224ipl/web is vulnerable to reflected XSS by malformed search requestsIcinga ipl-web
CVE-2026-24414Icinga for Windows certificate can have too-open permissionsicinga-powershell-framework
CVE-2026-24413Icinga has insecure permission of %ProgramData%\icinga2\var on WindowsIcinga icinga2
CVE-2025-61909Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon userIcinga icinga2
CVE-2025-61908Icinga 2 Denial of Service (DoS) By Dereferencing Invalid ReferenceIcinga icinga2
CVE-2025-61907Icinga 2 API users could access restricted values in filter expressionsIcinga icinga2
CVE-2025-61789Icinga DB Web hidden/protected custom variables are prone to filter enumerationIcinga icingadb-web
CVE-2025-53840Icinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerabilityIcinga icingadb-web
CVE-2025-48057Icinga 2 certificate renewal might incorrectly renew an invalid certificateIcinga icinga2
CVE-2025-30164Icinga Web 2 has open redirect on login pageIcinga icingaweb2
CVE-2025-27609Icinga Web 2 Vulnerable to Reflected XSSIcinga icingaweb2
CVE-2025-27406Icinga Reporting Stored XSS leads to SSRFIcinga icingaweb2-module-reporting
CVE-2025-27405Icinga Web 2 has XSS in embedded contentIcinga icingaweb2
CVE-2025-27404Icinga Web 2 DOM-based XSS vulnerabilityIcinga icingaweb2
CVE-2025-23203Icinga has rest API endpoints accessible to restricted usersIcinga icingaweb2-module-director
CVE-2024-49369Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API ConnectionsIcinga icinga2
CVE-2024-41811ipl/web susceptible to Cross-Site Request Forgery (CSRF)Icinga ipl-web
CVE-2024-24820Icinga Director configuration is susceptible to Cross-Site Request ForgeryIcinga icingaweb2-module-director
CVE-2024-24819icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRFIcinga icingaweb2-module-incubator
CVE-2023-30607icingaweb2-module-jira template and field configuration are susceptible to CSRFIcinga icingaweb2-module-jira
CVE-2022-24716Path traversal in Icinga Web 2Icinga icingaweb2
CVE-2022-24715Arbitrary code execution for authenticated users in Icinga Web 2Icinga icingaweb2
CVE-2022-24714Disclosure of hosts and related data, linked to decommissioned services in Icinga Web 2Icinga icingaweb2
CVE-2021-37698Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2WriterIcinga icinga2
CVE-2021-32747Custom variable protection and blacklists can be circumventedIcinga icingaweb2
CVE-2021-32746Possible path traversal by use of the `doc` moduleIcinga icingaweb2
CVE-2021-32743Passwords used to access external services inadvertently exposed through APIIcinga icinga2
CVE-2021-32739Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged)…Icinga icinga2

31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.