📦 Hertzbeat

by Apache

🔍 What is Hertzbeat?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51388

CRITICAL CVSS 9.8 Feb 22, 2024

This vulnerability allows remote code execution in Hertzbeat monitoring systems through AviatorScript injection. Attackers can execute arbitrary static methods by exploiting the unsecured expression e...

CVE-2023-51653

CRITICAL CVSS 9.8 Feb 22, 2024

This vulnerability in Hertzbeat allows remote code execution via JNDI injection in the JMX connector implementation. Attackers can exploit the /api/monitor/detect interface by providing a malicious JM...

CVE-2026-24343

HIGH CVSS 8.8 Feb 10, 2026

This XPath injection vulnerability in Apache HertzBeat allows attackers to manipulate XPath queries by injecting malicious data, potentially accessing or modifying sensitive information. It affects al...

CVE-2025-24404

HIGH CVSS 8.8 Sep 9, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on Apache HertzBeat servers by injecting malicious XML into HTTP sitemap responses. Attackers need authenticated access to a...

CVE-2024-45791

HIGH CVSS 7.5 Nov 18, 2024

Apache HertzBeat versions before 1.6.1 contain an information disclosure vulnerability that allows unauthorized actors to access sensitive information. This affects all users running vulnerable versio...

CVE-2024-42323

HIGH CVSS 8.8 Sep 21, 2024

This vulnerability allows authorized attackers to execute arbitrary code on Apache HertzBeat servers by exploiting insecure deserialization in SnakeYaml XML parsing. It affects all Apache HertzBeat (i...

CVE-2024-42361

HIGH CVSS 7.5 Aug 20, 2024

CVE-2024-42361 is a SQL injection vulnerability in Hertzbeat's monitoring endpoint that allows attackers to execute arbitrary SQL commands. This affects all Hertzbeat instances running version 1.6.0 o...

CVE-2023-51650

HIGH CVSS 7.5 Dec 22, 2023

Hertzbeat versions before 1.4.1 have Spring Boot permission misconfigurations that allow unauthenticated access to three interfaces. This vulnerability enables attackers to access sensitive server inf...