In LibreNMS versions 24.10.0 through 26.1.1 a medium severity vulnerability CVE-2026-27016 was detected. This vulnerability allows attackers to inject malicious scripts through the Custom OID unit parameter due to missing strip_tags() sanitization. The unsanitized input is stored in the database and rendered without proper HTML escaping, allowing stored cross-site scripting (XSS) attacks when the affected data is viewed. To address this issue, users should upgrade LibreNMS to version 26.2.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-27016.
Read more MonitoringIn LibreNMS versions 26.1.1 and below a medium severity vulnerability CVE-2026-26992 was detected. This vulnerability allows attackers with administrative privileges to inject and store malicious scripts through the unsanitized port group name parameter, which may execute when viewed by other users, potentially compromising their session or browser context. To address this issue, users should upgrade LibreNMS to version 26.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26992.
Read more MonitoringIn LibreNMS versions 25.12.0 and below a high severity vulnerability CVE-2026-26990 was detected. This vulnerability allows authenticated users to perform time-based blind SQL injection via the `address` parameter in `address-search.inc.php`, enabling attackers to infer database information by manipulating query logic and observing conditional response times. To address this issue, users should upgrade LibreNMS to version 26.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-26990.
Read more MonitoringIn changedetection.io versions prior to 0.53.2 a medium severity vulnerability CVE-2026-25527 was detected. This vulnerability allows unauthenticated attackers to read arbitrary local application files via a path traversal flaw in the `/static/<group>/<filename>` route, due to improper validation of the group parameter. To address this issue, users should upgrade changedetection.io to version 0.53.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-25527.
Read more MonitoringIn LibreNMS version 1.46 a high severity vulnerability CVE-2020-36947 was detected. This vulnerability allows authenticated attackers to extract sensitive database information by exploiting a SQL injection flaw in the MAC accounting graph endpoint via the manipulated sort parameter. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2020-36947.
Read more MonitoringIn LibreNMS versions prior to 25.12.0 a medium severity vulnerability CVE-2025-68614 was detected. This vulnerability allows attackers to inject arbitrary HTML or scripts via the Alert Rule API because alert rule names are not properly sanitized, leading to stored cross-site scripting (XSS) when the rules are viewed. To address this issue, users should upgrade LibreNMS to versions 25.12.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-68614.
Read more MonitoringIn Nagios XI versions prior to 2026R1.1 a high severity vulnerability CVE-2025-34288 was detected. This vulnerability allows attackers with local access to escalate privileges to root by abusing a sudo-executed maintenance script that includes a PHP file writable by a lower-privileged user, enabling malicious code injection and resulting in arbitrary code execution with root privileges when the script is run. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-34288.
Read more MonitoringIn Zabbix versions up to and including 7.0.5 and 6.4.15 a medium severity vulnerability CVE-2025-49643 was detected. This vulnerability allows an authenticated user, including the Guest account, to trigger excessive CPU consumption on the web server by supplying specially crafted parameters to the /imgstore.php endpoint. Successful exploitation can lead to a denial-of-service condition, degrading the availability of the Zabbix frontend. To address this issue, users should upgrade Zabbix to versions 7.0.6, 6.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49643.
In Zabbix Agent builds for AIX versions up to and including 7.0.5 and 6.4.15 a medium severity vulnerability CVE-2025-49642 was detected. This vulnerability allows local users with write access to the /home/cecuser directory to hijack library loading, potentially leading to arbitrary code execution or privilege escalation. To address this issue, users should upgrade Zabbix Agent to versions 7.0.6, 6.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49642.