Known vulnerabilities in cacti (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:cacti_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 18
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cacti (Debian package) cacti (Debian package) is affected by 18 known vulnerabilities: 1 critical, 3 high, 6 medium, 8 low Critical High Medium Low

Vulnerabilities (18)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU80438 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39516
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80437 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39515
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80436 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39514
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80435 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39513
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80434 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39512
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80433 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39365
CWE-89 Medium
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80432 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39510
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80431 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-39366
CWE-79 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80429 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-39362
CWE-78 Medium
Available
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 6 more
#VU80428 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39359
CWE-89 Medium
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 5 more
#VU80426 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-39364
CWE-601 Low
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 6 more
#VU80425 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39357
CWE-89 Medium
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 6 more
#VU80424 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-39361
CWE-89 High
No
No
1.2.16+ds1-2+deb11u2, 1.2.24+ds1-1+deb12u1 05.09.2023 SB2023090541
SB2023100429
SB2023100430
and 6 more
#VU70426 - Improper Authorization
CVE-2022-46169
CWE-285 Critical
Available
Exploited
1.2.16+ds1-2+deb11u1 19.12.2022 SB2022121926
SB2022121931
SB2023012480
and 6 more
#VU67763 - Improper Authentication
CVE-2022-0730
CWE-287 High
No
No
1.2.16+ds1-2+deb11u1 29.09.2022 SB2022092972
SB2022092973
SB2022121931
and 5 more
#VU23620 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2019-17357
CWE-89 Medium
No
No
0.8.8h+ds1-10+deb9u1, 1.2.2+ds1-2+deb10u2 16.12.2019 SB2019121614
SB2020012104
SB2020031923
and 7 more
#VU23619 - Deserialization of Untrusted Data
CVE-2019-17358
CWE-502 High
No
No
0.8.8h+ds1-10+deb9u1, 1.2.2+ds1-2+deb10u2 16.12.2019 SB2019121614
SB2020012104
SB2020031923
and 8 more
#VU21303 - Improper Access Control
CVE-2019-16723
CWE-284 Medium
No
No
0.8.8h+ds1-10+deb9u1, 1.2.2+ds1-2+deb10u2 24.09.2019 SB2019092410
SB2020012104
SB2020031923
and 9 more