Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi HIGH 8.8
CVE-2026-2041EPSS 73%

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2026-2042EPSS 6%

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2026-2043EPSS 73%

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2025-67255

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulne…

Mitigation only
Fix from $1,950 2025-12-29
Nagios Xi HIGH 7.5
CVE-2025-67254

NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

Mitigation only
Fix from $1,950 2025-12-29
Nagios Xi MEDIUM 6.7
CVE-2025-34288

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and applicati…

Fix: after 2024
Fix from $1,600 2025-12-16
Log Server HIGH 7.8
CVE-2025-34323

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-w…

Fix: 2026+
Fix from $1,950 2025-11-17
Log Server HIGH 7.2
CVE-2025-34322EPSS 9%

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries…

Fix: 2026+
Fix from $1,950 2025-11-17
Nagios Xi MEDIUM 6.5
CVE-2024-13998

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passw…

Fix: 2024+
Fix from $1,600 2025-11-03
Nagios Xi HIGH 7.2
CVE-2024-13997

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrat…

Fix: 2024+
Fix from $1,950 2025-11-03
Nagios Xi MEDIUM 5.4
CVE-2021-47698

Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escap…

Fix: 5.8.7+
Fix from $1,600 2025-11-03
Nagios Xi MEDIUM 5.4
CVE-2024-13992

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following…

Fix: 2024+
Fix from $1,600 2025-10-31
Log Server HIGH 8.8
CVE-2025-34298

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set th…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.8
CVE-2025-34287

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but own…

Fix: 2024+
Fix from $1,950 2025-10-30
Log Server CRITICAL 9.8
CVE-2025-34274

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash proces…

Fix: 2024+
Fix from $2,300 2025-10-30
Log Server CRITICAL 9.8
CVE-2025-34277

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated …

Fix: 2024+
Fix from $2,300 2025-10-30
Nagios Xi HIGH 8.8
CVE-2025-34284

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters…

Fix: 2024+
Fix from $1,950 2025-10-30
Network Analyzer HIGH 7.2
CVE-2025-34280

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2025-34286

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient va…

Fix: 2026+
Fix from $1,950 2025-10-30
Nagios Xi MEDIUM 6.5
CVE-2025-34283

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated …

Fix: 2024+
Fix from $1,600 2025-10-30
Network Analyzer MEDIUM 5.4
CVE-2025-34278

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calc…

Fix: 2024+
Fix from $1,600 2025-10-30
Log Server CRITICAL 9.8
CVE-2025-34271

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from pe…

Fix: 2024+
Fix from $2,300 2025-10-30
Log Server MEDIUM 6.5
CVE-2025-34272

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back…

Fix: 2024+
Fix from $1,600 2025-10-30
Log Server MEDIUM 6.5
CVE-2025-34273

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global …

Fix: 2024+
Fix from $1,600 2025-10-30
Nagios Xi HIGH 8.8
CVE-2024-14005

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input i…

Fix: 2024+
Fix from $1,950 2025-10-30
Log Server HIGH 7.8
CVE-2024-58273

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands …

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2024-14008

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2024-14009

Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2025-34134

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficie…

Fix: 2024+
Fix from $1,950 2025-10-30
Nagios Xi MEDIUM 6.1
CVE-2024-14006

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when …

Fix: 2024+
Fix from $1,600 2025-10-30