Vulnerability index

Browse CVEs

51 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Nagios Xi HIGH 8.8
CVE-2026-2041EPSS 73%

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2026-2042EPSS 6%

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2026-2043EPSS 73%

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…

Mitigation only
Fix from $1,950 2026-02-20
Nagios Xi HIGH 8.8
CVE-2025-67255

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulne…

Mitigation only
Fix from $1,950 2025-12-29
Nagios Xi HIGH 7.5
CVE-2025-67254

NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

Mitigation only
Fix from $1,950 2025-12-29
Fusion MEDIUM 6.1
CVE-2017-20209

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escapi…

Mitigation only
Fix from $1,600 2025-10-30
Fusion HIGH 8.6
CVE-2025-60425

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allo…

Mitigation only
Fix from $1,950 2025-10-27
Fusion HIGH 7.6
CVE-2025-60424

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a brut…

Mitigation only
Fix from $1,950 2025-10-27
Nagios Xi MEDIUM 6.1
CVE-2025-56432

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in t…

Mitigation only
Fix from $1,600 2025-08-26
Network Analyzer HIGH 7.5
CVE-2025-28059

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper sessi…

Mitigation only
Fix from $1,950 2025-04-18
Log Server HIGH 8.3
CVE-2025-29471EPSS 7%

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email …

No fix yet
Fix from $1,950 2025-04-15
Nagios Xi MEDIUM 6.1
CVE-2024-54957

Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability al…

Mitigation only
Fix from $1,600 2025-02-27
Nagios Xi MEDIUM 6.5
CVE-2024-54960

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab comp…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 6.5
CVE-2024-54961

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the username…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 6.1
CVE-2024-54958

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject ma…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 6.1
CVE-2024-54959

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scri…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 5.4
CVE-2024-42898

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in…

No fix yet
Fix from $1,600 2025-01-09
Nagios Xi CRITICAL 9.8
CVE-2024-33775

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

No fix yet
Fix from $2,300 2024-05-01
Nagios Xi CRITICAL 9.8
CVE-2024-24401EPSS 46%

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.p…

Mitigation only
Fix from $2,300 2024-02-26
Nagios Xi CRITICAL 9.8
CVE-2024-24402

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

Mitigation only
Fix from $2,300 2024-02-26
Nagios Xi MEDIUM 6.1
CVE-2020-23992

Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.

No fix yet
Fix from $1,600 2023-08-22
Nagios Xi CRITICAL 9.8
CVE-2022-38250

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

Mitigation only
Fix from $2,300 2022-09-07
Nagios Xi MEDIUM 6.1
CVE-2022-38249

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

Mitigation only
Fix from $1,600 2022-09-07
Nagios Xi HIGH 7.8
CVE-2021-40343

An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileg…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 7.2
CVE-2021-40344EPSS 66%

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary exten…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 7.2
CVE-2021-40345EPSS 23%

An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injec…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 8.8
CVE-2020-24899EPSS 17%

Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp q…

No fix yet
Fix from $1,950 2021-02-15
Nagios Xi HIGH 7.2
CVE-2020-22427EPSS 14%

NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a r…

No fix yet
Fix from $1,950 2021-02-15
Nagios Xi MEDIUM 6.1
CVE-2021-25299EPSS 98%

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php…

No fix yet
Fix from $1,600 2021-02-15
Nagios Core HIGH 8.8
CVE-2020-35269

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for host…

Mitigation only
Fix from $1,950 2020-12-23