Netalertx is a network monitoring and alerting application with a compact vulnerability footprint centered on its core product, where disclosed issues reflect application-layer security patterns around authentication, input validation, and access control. The recurring weakness classes—missing authentication for critical functions, path traversal, execution-after-redirect conditions, and comparison flaws—point to common patterns in web and network-facing applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netalertx over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48766HIGH NetAlertX 24.7.18 before 24.10.12 allows unauthenticated file reading because an HTTP client can ignore a redirect, and because of factors related to strpos and directory traversal | May 13, 2025 | 8.6 | 82 | NO | YES |
CVE-2024-46506CRITICAL NetAlertX 23.01.14 through 24.x before 24.10.12 allows unauthenticated command injection via settings update because function=savesettings lacks an authentication requirement, as e | May 13, 2025 | 10.0 | 82 | NO | YES |
CVE-2025-32440CRITICAL NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the authentication mechanism of NetAlertX to update settings withou | May 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-48952CRITICAL NetAlertX is a network, presence scanner, and alert framework. Prior to version 25.6.7, a vulnerability in the authentication logic allows users to bypass password verification usi | Jul 4, 2025 | 9.4 | 28 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netalertx.
Media articles that mention a CVE ID that affects a product developed by Netalertx — matched by CVE ID, not by vendor name.