Xymon is a systems and network monitoring platform with a focused product footprint that occupies a prominent role in enterprise monitoring infrastructure. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the exposure recurs through memory-safety issues such as buffer overflows and out-of-bounds writes alongside web-tier weaknesses including cross-site scripting and path traversal, reflecting both the native monitoring agent and web-interface components. Defenders should prioritize patching this vendor's releases given the combination of critical severity and public exploit availability, particularly for internet-reachable monitoring dashboards; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xymon over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2056HIGH xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) we | Apr 13, 2016 | 8.8 | 74 | NO | YES |
CVE-2016-2055HIGH xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command. | Apr 13, 2016 | 7.5 | 40 | NO | YES |
CVE-2019-13484CRITICAL In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c. | Aug 27, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-13486CRITICAL In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c. | Aug 27, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-13485CRITICAL In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c. | Aug 27, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-13455CRITICAL In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c. | Aug 27, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-13452CRITICAL In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c. | Aug 27, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-13451CRITICAL In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c. | Aug 27, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-13273CRITICAL In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf o | Aug 27, 2019 | 9.8 | 29 | NO | NO |
CVE-2016-2054CRITICAL Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service | Apr 13, 2016 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xymon.
Media articles that mention a CVE ID that affects a product developed by Xymon — matched by CVE ID, not by vendor name.