Known vulnerabilities in Icinga
Vendor:
Icinga
Software:
Icinga
Software CPE:
cpe:2.3:a:Icinga:icinga:*:*:*:*:*:*:*:*
Website:
https://github.com/Icinga
Total vulnerabilities:
13
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.16.4
2.16.3
2.15.5
2.14.10
2.16.2
2.15.4
2.14.9
v2.16.1
2.16.0
2.15.3
2.15.2
2.14.8
2.13.14
2.15.1
2.14.7
2.13.13
2.15.0
2.12.12
2.13.12
2.14.6
2.14.5
2.14.4
2.13.11
2.14.3
2.13.10
2.12.11
2.11.12
2.14.2
2.14.1
2.13.9
1.3.1
1.3.0
1.2.1
1.2.0
1.0.3
1.0.2
1.0.1
1.0
0.8.4
0.8.3
0.8.2
0.8.1
0.8.0
2.14.0
2.13.8
2.13.7
2.12.10
2.13.6
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.0.10
0.0.11
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.3.10
2.3.11
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.9.1
2.9.2
2.9.3
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.11.5
2.11.6
2.11.7
2.11.8
2.11.9
2.11.10
2.11.11
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.12.5
2.12.6
2.12.7
2.12.8
2.12.9
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
2.13.5
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU135839 - Improper Access Control |
CWE-284 | High | 2.14.9, 2.15.4, 2.16.2 | 29.06.2026 |
SB20260629126 |
||
| #VU135838 - Stack-based buffer overflow |
CWE-121 | High | 2.14.9, 2.15.4, 2.16.2 | 29.06.2026 |
SB20260629126 |
||
| #VU135837 - Improper input validation |
CWE-20 | Low | 2.14.9, 2.15.4, 2.16.2 | 29.06.2026 |
SB20260629126 |
||
| #VU122135 - Incorrect Default Permissions CVE-2026-24413 |
CWE-276 | Low | 2.13.14, 2.14.8, 2.15.2 | 30.01.2026 |
SB2026013004 |
||
| #VU117673 - Execution with Unnecessary Privileges CVE-2025-61909 |
CWE-250 | Low | 2.13.13, 2.14.7, 2.15.1 | 27.10.2025 |
SB2025102727 |
||
| #VU117672 - NULL Pointer Dereference CVE-2025-61908 |
CWE-476 | Medium | 2.13.13, 2.14.7, 2.15.1 | 27.10.2025 |
SB2025102727 |
||
| #VU117671 - Exposure of sensitive information to an unauthorized actor CVE-2025-61907 |
CWE-200 | Medium | 2.13.13, 2.14.7, 2.15.1 | 27.10.2025 |
SB2025102727 |
||
| #VU109861 - Improper Certificate Validation CVE-2025-48057 |
CWE-295 | High | 2.12.12, 2.13.12, 2.14.6 | 27.05.2025 |
SB2025052757 SB2025081374 |
||
| #VU135836 - Improper Certificate Validation CVE-2024-49369 |
CWE-295 | High | 2.11.12, 2.12.11, 2.13.10, 2.14.3 | 12.11.2024 |
SB20241112171 SB2024120709 |
||
| #VU135832 - Improper Certificate Validation CVE-2021-37698 |
CWE-295 | Medium | 2.7.0, 2.8.0, 2.9.0, 2.10.0, 2.11.0, 2.12.0, 2.13.0, 2.13.1 | 19.08.2021 |
SB2021081932 SB2024120709 |
||
| #VU135834 - Improper Access Control CVE-2021-32739 |
CWE-284 | Medium | 2.11.10, 2.12.5 | 15.07.2021 |
SB2021071543 SB2024120709 |
||
| #VU135833 - Improper Access Control CVE-2021-32743 |
CWE-284 | Low | 2.11.10, 2.12.5 | 15.07.2021 |
SB2021071543 SB2024120709 |
||
| #VU135835 - Improper Certificate Validation CVE-2020-29663 |
CWE-295 | Low | 2.11.8, 2.12.3 | 15.12.2020 |
SB2020121589 SB2024120709 |