Zenoss develops infrastructure monitoring and observability platforms that collect and analyze operational telemetry across enterprise IT environments, presenting a web-facing administrative attack surface. Its vulnerability profile centers on the Zenoss Core product and dashboard components, where the recurring weakness classes—sensitive information exposure, cross-site request forgery, cross-site scripting, and code injection—reflect the data-handling and web-interface demands of a monitoring application. The vendor's disclosures show an elevated tendency toward public exploit code availability, while live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zenoss over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-6261HIGH Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server | Dec 15, 2014 | 9.3 | 38 | NO | NO |
CVE-2014-6262HIGH Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or | Feb 12, 2020 | 7.5 | 27 | NO | NO |
CVE-2010-0713MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator f | Feb 26, 2010 | 6.8 | 27 | NO | YES |
CVE-2010-0712MEDIUM Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary S | Feb 26, 2010 | 6.5 | 27 | NO | YES |
CVE-2019-14257HIGH pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765. | Aug 21, 2019 | 7.8 | 26 | NO | NO |
CVE-2019-14258HIGH The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988. | Aug 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2014-6256HIGH Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2) execute access via a move act | Dec 15, 2014 | 7.5 | 23 | NO | NO |
CVE-2018-25063MEDIUM A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of the file ZenPacks/zenoss/Dashboar | Jan 1, 2023 | 6.1 | 22 | NO | NO |
CVE-2014-6260MEDIUM Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of se | Dec 15, 2014 | 6.8 | 22 | NO | NO |
CVE-2014-6255MEDIUM Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via th | Dec 15, 2014 | 6.4 | 22 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zenoss.
Media articles that mention a CVE ID that affects a product developed by Zenoss — matched by CVE ID, not by vendor name.