opsview CVE Vulnerabilities & Metrics

Focus on opsview vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About opsview Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with opsview. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total opsview CVEs: 11
Earliest CVE date: 05 Nov 2013, 20:55 UTC
Latest CVE date: 02 Jan 2020, 15:15 UTC

Latest CVE reference: CVE-2013-3936

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical opsview CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.01

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 12
7.0-8.9 1
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS opsview CVEs

These are the five CVEs with the highest CVSS scores for opsview, sorted by severity first and recency.

All CVEs for opsview

CVE-2013-3936 opsview vulnerability CVSS: 4.3 02 Jan 2020, 15:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.

CVE-2013-3935 opsview vulnerability CVSS: 6.8 02 Jan 2020, 15:15 UTC

Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.

CVE-2018-16148 opsview vulnerability CVSS: 4.3 05 Sep 2018, 21:29 UTC

The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.

CVE-2018-16147 opsview vulnerability CVSS: 4.3 05 Sep 2018, 21:29 UTC

The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.

CVE-2018-16146 opsview vulnerability CVSS: 9.0 05 Sep 2018, 21:29 UTC

The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurable events. The value parameter is not properly sanitized, leading to arbitrary command injection with the privileges of the nagios user account.

CVE-2018-16145 opsview vulnerability CVSS: 9.3 05 Sep 2018, 21:29 UTC

The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow attackers to elevate their privileges to root after a system restart, hence obtaining full control of the appliance.

CVE-2018-16144 opsview vulnerability CVSS: 10.0 05 Sep 2018, 21:29 UTC

The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password parameter.

CVE-2016-10368 opsview vulnerability CVSS: 5.8 03 May 2017, 10:59 UTC

Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.

CVE-2016-10367 opsview vulnerability CVSS: 5.0 03 May 2017, 10:59 UTC

In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request utilizing a simple URL encoding bypass, %252f instead of /.

CVE-2015-6035 opsview vulnerability CVSS: 4.3 10 Apr 2017, 03:59 UTC

Opsview before 2015-11-06 has XSS via SNMP.

CVE-2015-4420 opsview vulnerability CVSS: 4.3 18 Jun 2015, 18:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Test service check page.

CVE-2013-7256 opsview vulnerability CVSS: 6.8 03 Jan 2014, 18:54 UTC

Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2013-7255 opsview vulnerability CVSS: 5.8 03 Jan 2014, 18:54 UTC

Open redirect vulnerability in Opsview before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

CVE-2013-7254 opsview vulnerability CVSS: 4.3 03 Jan 2014, 18:54 UTC

Cross-site scripting (XSS) vulnerability in Opsview before 4.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2013-5695 opsview vulnerability CVSS: 4.3 05 Nov 2013, 20:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/auditlog/, (2) PATH_INFO to info/host/ or (3) viewport/, (4) back parameter to login, or (5) "from" parameter to status/service/recheck.

CVE-2013-5694 opsview vulnerability CVSS: 7.5 05 Nov 2013, 20:55 UTC

SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter.