Centreon operates a monitoring and observability platform deployed across enterprise infrastructure to track system performance and availability, and despite a focused product portfolio, occupies a prominent position in critical operational technology stacks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, making timely patching of this operational-layer software a high priority. The exposure recurs consistently across the platform's core product and its web-facing monitoring widgets, and clusters around input-handling weakness classes including SQL injection, cross-site scripting, OS command injection, forced browsing, and path traversal—attack surfaces characteristic of web-based administrative interfaces that accept and process untrusted data from users and external systems. Defenders should treat Centreon advisories with urgency given the vendor's placement in observability infrastructure and the severity of flaws that arise in its authentication and data-handling paths; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Centreon over time
Of all the CVEs published by Centreon as a CNA, 90.9% affect products that Centreon develops as a vendor.
Of all the CVEs published that affect products developed by Centreon, 24.2% are self-published by Centreon as a CNA.
Signals from CVEs in this vendor scope (124 CVEs).
124 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42429HIGH This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw | Mar 29, 2023 | 8.8 | 69 | NO | NO |
CVE-2022-42425HIGH This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw | Mar 29, 2023 | 8.8 | 68 | NO | NO |
CVE-2022-42424HIGH This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw | Mar 29, 2023 | 8.8 | 68 | NO | NO |
CVE-2022-41142HIGH This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw | Jan 26, 2023 | 8.8 | 68 | NO | NO |
CVE-2024-0637HIGH Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centre | Apr 1, 2024 | 8.8 | 64 | NO | NO |
CVE-2022-42427HIGH This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw | Mar 29, 2023 | 8.8 | 63 | NO | NO |
CVE-2019-13024HIGH Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitor | Jul 1, 2019 | 8.8 | 57 | NO | YES |
CVE-2024-23115HIGH Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. | Apr 1, 2024 | 7.2 | 56 | NO | NO |
CVE-2024-5725HIGH Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon | Aug 21, 2024 | 8.8 | 51 | NO | NO |
CVE-2024-23118HIGH Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Apr 1, 2024 | 7.2 | 50 | NO | NO |
Signals from CVEs in this vendor scope (124 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Centreon.
Media articles that mention a CVE ID that affects a product developed by Centreon — matched by CVE ID, not by vendor name.