Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Paessler

First CVE: Aug 31, 2006Active for: 20 yearsTotal CVEs: 41
55.3
VTI Score
TOP TARGET

Paessler develops a focused portfolio of network and infrastructure monitoring appliances, with its flagship PRTG Network Monitor product serving as a central visibility and alerting platform in managed IT environments. The vendor's vulnerability profile clusters around web-application and input-handling issues—cross-site scripting, path traversal, improper input validation, and cross-site request forgery—reflecting the web-facing nature of its monitoring dashboards and configuration interfaces. Public exploit code has frequently been made available for this vendor's disclosures, consistent with the appeal of monitoring systems as targets for reconnaissance and lateral movement. Defenders should treat updates to these monitoring platforms as operationally urgent, since compromise can enable broad visibility into the monitored infrastructure; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
41
Total CVEs
More Total CVEs than 98% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
4.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Paessler over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2006
19 years ago
Most Recent CVE
Jan 14, 2026
191 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (41 CVEs).

41 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-19410CRITICAL
PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user
Nov 21, 20189.897YESYES
CVE-2018-9276HIGH
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit a
Jul 2, 20187.297YESYES
CVE-2023-32782HIGH
A command injection was identified in PRTG 23.2.84.1566 and earlier versions in the Dicom C-ECHO sensor where an authenticated user with write permissions could abuse the debug opt
Aug 9, 20237.250NONO
CVE-2020-11547MEDIUM
PRTG Network Monitor before 20.1.57.1745 allows remote unauthenticated attackers to obtain information about probes running or the server itself (CPU usage, memory, Windows version
Apr 5, 20205.350NOYES
CVE-2023-32781HIGH
A command injection vulnerability was identified in PRTG 23.2.84.1566 and earlier versions in the HL7 sensor where an authenticated user with write permissions could abuse the debu
Aug 9, 20237.233NOYES
CVE-2020-14073MEDIUM
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can create a map, and then use the Map Designer Properties screen
Jun 23, 20205.431NOYES
CVE-2020-10374CRITICAL
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of t
Mar 30, 20209.831NONO
CVE-2018-10253HIGH
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
Apr 21, 20187.531NOYES
CVE-2018-19204HIGH
PRTG Network Monitor before 18.3.44.2054 allows a remote authenticated attacker (with read-write privileges) to execute arbitrary code and OS commands with system privileges. When
Nov 12, 20188.829NONO
CVE-2018-19411HIGH
PRTG Network Monitor before 18.2.40.1683 allows an authenticated user with a read-only account to create another user with a read-write account (including administrator) via an HTT
Nov 21, 20188.827NONO
View all 41 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products41 CVEs
68%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (4.9%)
Network37 (90.2%)
Unknown2 (4.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (95.1%)
High0 (0.0%)
Unknown2 (4.9%)
User Interaction
None22 (53.7%)
Unknown2 (4.9%)
Required17 (41.5%)
Privileges Required
Low10 (24.4%)
High10 (24.4%)
None19 (46.3%)
Unknown2 (4.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (41 CVEs).

CISA KEV
2 CVEs
4.9% of CVEs· 99th percentile
Metasploit
2 CVEs
4.9% of CVEs· 98th percentile
Nuclei
2 CVEs
4.9% of CVEs· 96th percentile
ExploitDB
3 CVEs
7.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Paessler.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Paessler — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Paessler's Products

View all 3 CNAs →

Top CWEs