Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Icinga

First CVE: Jun 14, 2011Active for: 15 yearsTotal CVEs: 49
44.1
VTI Score
High

Icinga operates a well-regarded open-source monitoring and observability platform that spans a core engine, web interfaces, and integrations, positioning itself as a prominent member of the infrastructure-monitoring landscape despite a modestly sized product portfolio. Vulnerabilities affecting the vendor frequently acquire public exploit code and concentrate in the web-facing components—particularly the Icinga Web 2 interface and related administrative dashboards—where they manifest as input-validation and authentication weaknesses including cross-site scripting, cross-site request forgery, path traversal, and improper certificate validation. These weakness classes reflect the web-application and user-input handling demands of a distributed monitoring platform that often sits in privileged network positions with access to critical operational data. Defenders should treat Icinga updates as moderately urgent for exposed or internet-connected instances, since the platform's administrative scope and the tendency toward exploit availability warrant timely remediation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
49
Total CVEs
More Total CVEs than 98% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Icinga over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 14, 2011
15 years ago
Most Recent CVE
Jan 29, 2026
176 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24716HIGH
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible t
Mar 8, 20227.587NOYES
CVE-2012-6096HIGH
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.
Jan 22, 20137.579NOYES
CVE-2013-7108MEDIUM
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain se
Jan 15, 20145.563NOYES
CVE-2022-24715HIGH
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files
Mar 8, 20228.847NOYES
CVE-2011-2179MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script
Jun 14, 20114.340NOYES
CVE-2024-49369CRITICAL
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate valid
Nov 12, 20249.829NONO
CVE-2020-29663CRITICAL
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2
Dec 15, 20209.129NONO
CVE-2025-48057CRITICAL
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.
May 27, 20259.828NONO
CVE-2021-32739HIGH
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 throug
Jul 15, 20218.828NONO
CVE-2018-18249CRITICAL
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name
Dec 17, 20189.828NONO
View all 49 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products49 CVEs
51%
37%
8%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (16.3%)
Network32 (65.3%)
Unknown9 (18.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (75.5%)
High3 (6.1%)
Unknown9 (18.4%)
User Interaction
None27 (55.1%)
Unknown9 (18.4%)
Required13 (26.5%)
Privileges Required
Low17 (34.7%)
High2 (4.1%)
None21 (42.9%)
Unknown9 (18.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.1% of CVEs· 98th percentile
Nuclei
1 CVE
2.0% of CVEs· 95th percentile
ExploitDB
5 CVEs
10.2% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Icinga.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Icinga — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Icinga's Products

View all 3 CNAs →

Top CWEs