CVE Tools

Horizon

61 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Horizon, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Horizon CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Horizon CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-062
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-051
2026-061
2026-070
2026-082
2026-093

Severity

How the 61 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High1119%
  • Medium4271%
  • Low610%

Latest CVEs

The 15 most recently published vulnerabilities affecting Horizon.

  1. CVE-2026-89089OpenNMS SQL injection in shipped Asset Management JasperReports via the DATE_FORMAT parameter (ROLE_USER)6.5
  2. CVE-2026-19596OpenNMS XML collector XXE allows arbitrary file read from the OpenNMS host5.9
  3. CVE-2026-89054OpenNMS missing authorization on /api/v2 PATCH endpoints allows unauthenticated configuration changes8.2
  4. CVE-2026-19182OpenNMS v2 Alarm REST API inverted authorization check lets ROLE_REST users acknowledge alarms as any user and bypass read-only4.3
  5. CVE-2026-19135OpenNMS JEXL sandbox bypass in Measurements REST API allows ROLE_USER to load arbitrary classes5.4
  6. CVE-2026-55748OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security harden...6.0
  7. CVE-2026-43002An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauth...5.3
  8. CVE-2026-22420WordPress Horizon theme <= 1.1 - Local File Inclusion vulnerability8.1
  9. CVE-2025-53122SQLi in OpenNMS Horizon and Meridian—
  10. CVE-2025-53121Stored XSS in multiple 33.0.8files in opennms/opennms—
  11. CVE-2023-40314Cross-site scripting in bootstrap.jsp5.8
  12. CVE-2023-40612Authenticated XXE Injection Via The File Editor5.3
  13. CVE-2022-45582Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.6.1
  14. CVE-2023-40315ROLE_FILESYSTEM_EDITOR Can Be Used To Escalate To ROLE_ADMIN5.3
  15. CVE-2023-40313Disable BeanShell Interpreter Remote Server Mode7.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store