Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zenoss

First CVE: Feb 26, 2010Active for: 16 yearsTotal CVEs: 26
31.7
VTI Score
Medium

Zenoss develops infrastructure monitoring and observability platforms that collect and analyze operational telemetry across enterprise IT environments, presenting a web-facing administrative attack surface. Its vulnerability profile centers on the Zenoss Core product and dashboard components, where the recurring weakness classes—sensitive information exposure, cross-site request forgery, cross-site scripting, and code injection—reflect the data-handling and web-interface demands of a monitoring application. The vendor's disclosures show an elevated tendency toward public exploit code availability, while live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zenoss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 26, 2010
16 years ago
Most Recent CVE
Jan 1, 2023
1,300 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-6261HIGH
Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server
Dec 15, 20149.338NONO
CVE-2014-6262HIGH
Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or
Feb 12, 20207.527NONO
CVE-2010-0713MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss 2.3.3, and other versions before 2.5, allow remote attackers to hijack the authentication of an administrator f
Feb 26, 20106.827NOYES
CVE-2010-0712MEDIUM
Multiple SQL injection vulnerabilities in zport/dmd/Events/getJSONEventsInfo in Zenoss 2.3.3, and other versions before 2.5, allow remote authenticated users to execute arbitrary S
Feb 26, 20106.527NOYES
CVE-2019-14257HIGH
pyraw in Zenoss 2.5.3 allows local privilege escalation by modifying environment variables to redirect execution before privileges are dropped, aka ZEN-31765.
Aug 21, 20197.826NONO
CVE-2019-14258HIGH
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
Aug 21, 20197.525NONO
CVE-2014-6256HIGH
Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2) execute access via a move act
Dec 15, 20147.523NONO
CVE-2018-25063MEDIUM
A vulnerability classified as problematic was found in Zenoss Dashboard up to 1.3.4. Affected by this vulnerability is an unknown functionality of the file ZenPacks/zenoss/Dashboar
Jan 1, 20236.122NONO
CVE-2014-6260MEDIUM
Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of se
Dec 15, 20146.822NONO
CVE-2014-6255MEDIUM
Open redirect vulnerability in the login form in Zenoss Core before 4.2.5 SP161 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via th
Dec 15, 20146.422NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
73%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (3.8%)
Network3 (11.5%)
Unknown22 (84.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (15.4%)
High0 (0.0%)
Unknown22 (84.6%)
User Interaction
None3 (11.5%)
Unknown22 (84.6%)
Required1 (3.8%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None3 (11.5%)
Unknown22 (84.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
11.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zenoss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zenoss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zenoss's Products

View all 3 CNAs →

Top CWEs