CVE Tools

Eyesofnetwork

29 CVEs tracked since 2017. Since Sep 2017, 2 of them reached CISA KEV.

Eyesofnetwork CVEs per month

Sep 2017 to Nov 2022. Point at a month, or focus the strip and use the arrow keys.
Eyesofnetwork CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-09100
2017-1070
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-0252
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-1020
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-0220
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-1130

Products

The products that kept showing up in Eyesofnetwork's monthly top three, with their CVEs summed over those months.

  1. Eyesofnetwork265 months
  2. Web Interface31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Eyesofnetwork.

  1. CVE-2022-41572An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the s...9.8
  2. CVE-2022-41434EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /lilac/main.php.6.1
  3. CVE-2022-41432EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/report_event/index.php.4.8
  4. CVE-2022-41433EyesOfNetwork Web Interface v5.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /module/admin_bp/add_application.php.4.8
  5. CVE-2022-41571An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Local file inclusion can occur.9.8
  6. CVE-2022-41570An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Unauthenticated SQL injection can occur.9.8
  7. CVE-2021-40643EyesOfNetwork before 07-07-2021 has a Remote Code Execution vulnerability on the mail options configuration page. In the location of the "sendmail" application in the "cacti" configuration page (by...9.8
  8. CVE-2022-24612An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in a stored XSS.5.4
  9. CVE-2021-33525EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+cur...8.8
  10. CVE-2021-27513The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."8.8
  11. CVE-2021-27514EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).9.8
  12. CVE-2020-27887An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the nmap_binar...8.8
  13. CVE-2020-27886An issue was discovered in EyesOfNetwork eonweb 5.3-7 through 5.3-8. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to exploit the username_available fun...9.8
  14. CVE-2020-24390eonweb in EyesOfNetwork before 5.3-7 does not properly escape the username on the /module/admin_logs page, which might allow pre-authentication stored XSS during login/logout logs recording.6.1
  15. CVE-2020-9465An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL injection, allowing an unauthenticated attacker to perform various tasks suc...9.8

The record

Peak rank
#33 in Sep 2017
Busiest month shown
Sep 2017, 10 CVEs
Months with a KEV entry
1 since Sep 2017
Monthly snapshots
6 since 2017
Eyesofnetwork's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store