VendorsApachehertzbeatall versions
Vulnerabilities

Apache Software Foundation HertzBeat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-51653
Hertzbeat JMX JNDI RCE
Published 2024-02-22 · Analyzed
9.8EPSS 0.021
CVE-2023-51388
HertzBeat AviatorScript Inject RCE
Published 2024-02-22 · Analyzed
9.8EPSS 0.013
CVE-2023-51389
HertzBeat SnakeYAML Deser RCE
Published 2024-02-22 · Analyzed
9.8EPSS 0.013
CVE-2024-42361
GHSL-2023-256: HertzBeat Authenticated (guest role) SQL injection in /api/monitor/{monitorId}/metric/{metricFull}
Published 2024-08-20 · Analyzed
9.8EPSS 0.011
CVE-2024-42323
Apache HertzBeat: RCE by snakeYaml deser load malicious xml
Published 2024-09-21 · Analyzed
8.8EPSS 0.083
CVE-2024-45505
Apache HertzBeat: Exists Native Deser RCE and file writing vulnerabilities
Published 2024-11-18 · Analyzed
8.8EPSS 0.022
CVE-2023-51387
Expression Injection Vulnerability in Hertzbeat
Published 2023-12-22 · Modified
8.8EPSS 0.014
CVE-2024-42362
GHSL-2023-255: HertzBeat Authenticated (user role) RCE via unsafe deserialization in /api/monitors/import
Published 2024-08-20 · Analyzed
8.8EPSS 0.013
CVE-2024-41151
Apache HertzBeat: RCE by notice template injection vulnerability
Published 2024-11-18 · Analyzed
8.8EPSS 0.010
CVE-2026-24343
Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
Published 2026-02-10 · Analyzed
8.8EPSS 0.007
CVE-2025-48208
Apache HertzBeat (incubating): Jmx JNDI injection vulnerability
Published 2025-09-09 · Modified
8.8EPSS 0.006
CVE-2025-24404
Apache HertzBeat (incubating): RCE by parse http sitemap xml response
Published 2025-09-09 · Modified
8.8EPSS 0.005
CVE-2022-39337
Permission bypass due to incorrect configuration in github.com/dromara/hertzbeat
Published 2023-12-22 · Modified
7.5EPSS 0.011
CVE-2023-51650
Unauthorized access vulnerability on three interfaces
Published 2023-12-22 · Modified
7.5EPSS 0.009
CVE-2024-45791
Apache HertzBeat: Exposure sensitive token via http GET method with query string
Published 2024-11-18 · Analyzed
7.5EPSS 0.008
CVE-2024-56736
Apache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config Oss
Published 2025-04-16 · Analyzed
6.5EPSS 0.007