Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Centreon

First CVE: Dec 20, 2007Active for: 19 yearsTotal CVEs: 124
58.0
VTI Score
TOP TARGET

Centreon operates a monitoring and observability platform deployed across enterprise infrastructure to track system performance and availability, and despite a focused product portfolio, occupies a prominent position in critical operational technology stacks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, making timely patching of this operational-layer software a high priority. The exposure recurs consistently across the platform's core product and its web-facing monitoring widgets, and clusters around input-handling weakness classes including SQL injection, cross-site scripting, OS command injection, forced browsing, and path traversal—attack surfaces characteristic of web-based administrative interfaces that accept and process untrusted data from users and external systems. Defenders should treat Centreon advisories with urgency given the vendor's placement in observability infrastructure and the severity of flaws that arise in its authentication and data-handling paths; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
124
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Centreon over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2007
18 years ago
Most Recent CVE
Feb 27, 2026
147 days ago

Self-Reporting Analysis

Of all the CVEs published by Centreon as a CNA, 90.9% affect products that Centreon develops as a vendor.

90.9%
Self-reported: 30 (90.9%)
Third-party: 3 (9.1%)

Of all the CVEs published that affect products developed by Centreon, 24.2% are self-published by Centreon as a CNA.

24.2%
75.8%
Self-published: 30 (24.2%)
Other CNAs: 94 (75.8%)

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (124 CVEs).

124 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-42429HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw
Mar 29, 20238.869NONO
CVE-2022-42425HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw
Mar 29, 20238.868NONO
CVE-2022-42424HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw
Mar 29, 20238.868NONO
CVE-2022-41142HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw
Jan 26, 20238.868NONO
CVE-2024-0637HIGH
Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centre
Apr 1, 20248.864NONO
CVE-2022-42427HIGH
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw
Mar 29, 20238.863NONO
CVE-2019-13024HIGH
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitor
Jul 1, 20198.857NOYES
CVE-2024-23115HIGH
Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon.
Apr 1, 20247.256NONO
CVE-2024-5725HIGH
Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon
Aug 21, 20248.851NONO
CVE-2024-23118HIGH
Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Apr 1, 20247.250NONO
View all 124 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products124 CVEs
36%
49%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (1.6%)
Network115 (92.7%)
Unknown6 (4.8%)
Physical0 (0.0%)
Adjacent Network1 (0.8%)
Attack Complexity
Low118 (95.2%)
High0 (0.0%)
Unknown6 (4.8%)
User Interaction
None84 (67.7%)
Unknown6 (4.8%)
Required34 (27.4%)
Privileges Required
Low50 (40.3%)
High32 (25.8%)
None36 (29.0%)
Unknown6 (4.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (124 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
5.6% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Centreon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Centreon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Centreon's Products

View all 4 CNAs →

Top CWEs