Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2020-5796
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, result…
Nagios Xi
No fix yet
HIGH 7.2
CVE-2020-5792EPSS 61%
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files …
Nagios Xi
No fix yet
MEDIUM 6.5
CVE-2020-5790
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into cli…
Nagios Xi
No fix yet
HIGH 8.8
CVE-2020-6585
Nagios Log Server 2.1.3 has CSRF.
Nagios
No fix yet
MEDIUM 6.5
CVE-2020-6584
Nagios Log Server 2.1.3 has Incorrect Access Control.
Nagios
No fix yet
MEDIUM 5.4
CVE-2020-6586EPSS 19%
Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious …
Nagios
Mitigation only
HIGH 8.8
CVE-2019-20197EPSS 22%
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php…
Nagios Xi
No fix yet
MEDIUM 5.4
CVE-2019-20139EPSS 26%
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency param…
Nagios Xi
No fix yet
CRITICAL 9.8
CVE-2019-12279
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this…
Nagios Xi
No fix yet
CRITICAL 9.8
CVE-2018-15708EPSS 89%
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nagios Xi
No fix yet
HIGH 8.8
CVE-2018-15709EPSS 21%
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nagios Xi
No fix yet
HIGH 8.8
CVE-2018-15711EPSS 36%
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new…
Nagios Xi
No fix yet
HIGH 7.8
CVE-2018-15710EPSS 44%
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
Nagios Xi
No fix yet
MEDIUM 6.1
CVE-2018-15712EPSS 49%
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
Nagios Xi
No fix yet
MEDIUM 6.1
CVE-2018-15714
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
Nagios Xi
No fix yet
MEDIUM 5.4
CVE-2018-15713EPSS 7%
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
Nagios Xi
No fix yet
MEDIUM 6.5
CVE-2018-10553EPSS 39%
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginn…
Nagios Xi
Mitigation only
MEDIUM 5.4
CVE-2018-10554
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm pa…
Nagios Xi
No fix yet
CRITICAL 9.8
CVE-2016-0726
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote at…
Nagios
Mitigation only
MEDIUM 6.1
CVE-2016-6209
Cross-site scripting (XSS) vulnerability in Nagios.
Nagios
No fix yet
MEDIUM 5.0
CVE-2007-5623
Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via…
Plugins
Mitigation only