Known vulnerabilities in cacti (Alpine package)

Software CPE: cpe:2.3:o:alpine:cacti_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 20
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cacti (Alpine package) cacti (Alpine package) is affected by 20 known vulnerabilities: 6 high, 7 medium, 7 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU31874 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2020-14295
CWE-89 Medium
Available
No
- 26.07.2020 SB2020072602
SB2020072603
SB1970010101
and 7 more
#VU29531 - Improper input validation
CVE-2020-13625
CWE-20 Low
No
No
- 06.07.2020 SB2020070602
SB2020072602
SB2020072603
and 10 more
#VU27519 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11023
CWE-79 Low
Available
Exploited
- 05.05.2020 SB2020042126
SB2020052033
SB2020052103
and 180 more
#VU27052 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-11022
CWE-79 Low
Available
No
- 21.04.2020 SB2020042126
SB2020052033
SB2020052103
and 181 more
#VU25543 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-8813
CWE-78 High
Available
No
1.2.10-r0 24.02.2020 SB2020022410
SB2020050102
SB2020031332
and 8 more
#VU24394 - Improper input validation
CVE-2020-7237
CWE-20 High
No
No
1.2.10-r0 20.01.2020 SB2020011616
SB2020031923
SB2020031331
and 9 more
#VU24356 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2020-7106
CWE-79 Low
No
No
1.2.10-r0 16.01.2020 SB2020011616
SB2020031923
SB2020051147
and 11 more
#VU23619 - Deserialization of Untrusted Data
CVE-2019-17358
CWE-502 High
No
No
1.2.8-r0, 1.2.10-r0 16.12.2019 SB2019121614
SB2020012104
SB2020031923
and 8 more
#VU33274 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2016-3172
CWE-89 High
No
No
0.8.8g-r1 12.04.2016 SB2016041220
SB2016080533
#VU33280 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-8604
CWE-89 High
No
No
0.8.8f-r2 12.04.2016 SB2016041221
SB2016030401
SB2016032409
#VU33277 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2016-3659
CWE-89 High
No
No
0.8.8g-r0 11.04.2016 SB2016041108
SB2016053012
SB2016060212
and 5 more
#VU33281 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-8369
CWE-89 Medium
No
No
0.8.8f-r1 17.12.2015 SB2015121704
SB2016012730
#VU33278 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-8377
CWE-89 Low
No
No
0.8.8g-r0, 0.8.8f-r3 15.12.2015 SB2015121512
SB2016031806
SB2016032409
#VU32404 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-4634
CWE-89 Medium
No
No
0.8.8f-r0 11.08.2015 SB2015081111
SB2015073107
SB2016032409
#VU32418 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2015-4342
CWE-89 Medium
No
No
0.8.8d-r0 17.06.2015 SB2015061701
SB2015061522
SB2016032409
and 3 more
#VU33649 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2014-5025
CWE-79 Low
No
No
0.8.8b-r2 20.10.2014 SB2014102002
SB2014073003
SB2016032409
#VU33656 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2014-5026
CWE-79 Low
No
No
0.8.8b-r2 20.10.2014 SB2014102003
SB2014073004
SB2016032409
#VU32633 - Improper Control of Generation of Code ('Code Injection')
CVE-2013-1435
CWE-94 Medium
No
No
0.8.8b-r0 23.08.2013 SB2013082302
SB2013080606
SB2013090401
and 2 more
#VU32632 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2013-1434
CWE-89 Medium
No
No
0.8.8b-r0 23.08.2013 SB2013082301
SB2013080605
SB2013090401
and 2 more
#VU32836 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2011-4824
CWE-89 Medium
No
No
0.8.7i-r0 15.12.2011 SB2011121502
SB2012010703