Known vulnerabilities in Icinga
Vendor:
Icinga
Software:
Icinga
Software CPE:
cpe:2.3:a:Icinga:icinga:*:*:*:*:*:*:*:*
Website:
https://github.com/Icinga
Total vulnerabilities:
15
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2.11.0-rc1
2.12.0-rc1
2.16.5
2.15.6
2.16.4
2.16.3
2.15.5
2.14.10
2.16.2
2.15.4
2.14.9
v2.16.1
2.16.0
2.15.3
2.15.2
2.14.8
2.13.14
2.15.1
2.14.7
2.13.13
2.15.0
2.12.12
2.13.12
2.14.6
2.14.5
2.14.4
2.13.11
2.14.3
2.13.10
2.12.11
2.11.12
2.14.2
2.14.1
2.13.9
1.3.1
1.3.0
1.2.1
1.2.0
1.0.3
1.0.2
1.0.1
1.0
0.8.4
0.8.3
0.8.2
0.8.1
0.8.0
2.14.0
2.13.8
2.13.7
2.12.10
2.13.6
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.0.10
0.0.11
2.0.0
2.0.1
2.0.2
2.1.0
2.1.1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.3.10
2.3.11
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.6.1
2.6.2
2.6.3
2.7.0
2.7.1
2.7.2
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.9.0
2.9.1
2.9.2
2.9.3
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.10.5
2.10.6
2.10.7
2.11.0
2.11.1
2.11.2
2.11.3
2.11.4
2.11.5
2.11.6
2.11.7
2.11.8
2.11.9
2.11.10
2.11.11
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.12.5
2.12.6
2.12.7
2.12.8
2.12.9
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
2.13.5
Vulnerabilities (15)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU144223 - Improper Access Control |
CWE-284 | Low | 2.15.6, 2.16.5 | 18.08.2026 |
SB2026081869 |
||
| #VU144222 - Allocation of Resources Without Limits or Throttling |
CWE-770 | Low | 2.15.6, 2.16.5 | 18.08.2026 |
SB2026081869 |
||
| #VU135839 - Improper Access Control CVE-2026-61550 |
CWE-284 | High | 2.14.9, 2.15.4, 2.16.2 | 29.06.2026 |
SB20260629126 SB2026092264 |
||
| #VU135838 - Stack-based buffer overflow CVE-2026-61551 |
CWE-121 | High | 2.14.9, 2.15.4, 2.16.2 | 29.06.2026 |
SB20260629126 SB2026092264 |
||
| #VU135837 - Improper input validation CVE-2026-61552 |
CWE-20 | Low | 2.14.9, 2.15.4, 2.16.2 | 29.06.2026 |
SB20260629126 SB2026092264 |
||
| #VU122135 - Incorrect Default Permissions CVE-2026-24413 |
CWE-276 | Low | 2.13.14, 2.14.8, 2.15.2 | 30.01.2026 |
SB2026013004 |
||
| #VU117673 - Execution with Unnecessary Privileges CVE-2025-61909 |
CWE-250 | Low | 2.13.13, 2.14.7, 2.15.1 | 27.10.2025 |
SB2025102727 SB2026092264 |
||
| #VU117672 - NULL Pointer Dereference CVE-2025-61908 |
CWE-476 | Medium | 2.13.13, 2.14.7, 2.15.1 | 27.10.2025 |
SB2025102727 SB2026092264 |
||
| #VU117671 - Exposure of sensitive information to an unauthorized actor CVE-2025-61907 |
CWE-200 | Medium | 2.13.13, 2.14.7, 2.15.1 | 27.10.2025 |
SB2025102727 SB2026092264 |
||
| #VU109861 - Improper Certificate Validation CVE-2025-48057 |
CWE-295 | High | 2.12.12, 2.13.12, 2.14.6 | 27.05.2025 |
SB2025052757 SB2025081374 |
||
| #VU135836 - Improper Certificate Validation CVE-2024-49369 |
CWE-295 | High | 2.11.12, 2.12.11, 2.13.10, 2.14.3 | 12.11.2024 |
SB20241112171 SB2024120709 |
||
| #VU135832 - Improper Certificate Validation CVE-2021-37698 |
CWE-295 | Medium | 2.7.0, 2.8.0, 2.9.0, 2.10.0, 2.11.0, 2.12.0, 2.13.0, 2.13.1 | 19.08.2021 |
SB2021081932 SB2024120709 |
||
| #VU135834 - Improper Access Control CVE-2021-32739 |
CWE-284 | Medium | 2.11.10, 2.12.5 | 15.07.2021 |
SB2021071543 SB2024120709 |
||
| #VU135833 - Improper Access Control CVE-2021-32743 |
CWE-284 | Low | 2.11.10, 2.12.5 | 15.07.2021 |
SB2021071543 SB2024120709 |
||
| #VU135835 - Improper Certificate Validation CVE-2020-29663 |
CWE-295 | Low | 2.11.8, 2.12.3 | 15.12.2020 |
SB2020121589 SB2024120709 |