Merethis develops Centreon, a widely deployed open-source monitoring and observability platform that provides visibility across infrastructure and applications; its vulnerability footprint concentrates in this single product line. The recurring weakness classes—SQL injection, code injection, and path traversal—reflect the challenges of safely handling user input and file paths in a web-based administrative interface, and public exploit code has frequently become available for disclosed flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Merethis over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3828HIGH Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands v | Oct 23, 2014 | 10.0 | 86 | NO | YES |
CVE-2014-3829HIGH displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metachar | Oct 23, 2014 | 10.0 | 84 | NO | YES |
CVE-2011-4431MEDIUM Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to execute arbitrary commands via a .. (dot dot) in the command_na | Nov 10, 2011 | 6.5 | 35 | NO | YES |
CVE-2012-5967MEDIUM SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote authenticated users to execute arbitrary SQL commands via t | Dec 19, 2012 | 6.5 | 31 | NO | YES |
CVE-2010-1301HIGH SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via the host_id parameter. | Apr 7, 2010 | 7.5 | 30 | NO | YES |
CVE-2009-4368HIGH Multiple unspecified vulnerabilities in Centreon before 2.1.4 have unknown impact and attack vectors in the (1) ping tool, (2) traceroute tool, and (3) ldap import, possibly relate | Dec 21, 2009 | 10.0 | 25 | NO | NO |
CVE-2011-4432MEDIUM www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for c | Nov 10, 2011 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Merethis.
Media articles that mention a CVE ID that affects a product developed by Merethis — matched by CVE ID, not by vendor name.