Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi HIGH 8.8
CVE-2021-47693

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search text ha…

Fix: 5.8.5+
Fix from $1,950 2025-10-30
Nagios Xi MEDIUM 6.1
CVE-2021-47694

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerabilit…

Fix: 5.8.6+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2021-47689

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting (XSS) vulnerability in the Te…

Fix: 5.8.0+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2021-47690

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities…

Fix: 5.8.2+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2021-47691

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities…

Fix: 5.8.2+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2021-47695

Nagios XI versions prior to 5.8.0 are vulnerable to stored cross-site scripting (XSS) via the My Tools page. Insufficient validation or escaping of u…

Fix: 5.8.0+
Fix from $1,600 2025-10-30
Nagios Xi HIGH 8.8
CVE-2020-36863

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler di…

Fix: 5.7.2+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2020-36867

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values use…

Fix: 5.7.3+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.8
CVE-2020-36868

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retri…

Fix: 5.7.3+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2020-36869

Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with a…

Fix: 5.7.5+
Fix from $1,950 2025-10-30
Nagios Xi MEDIUM 6.1
CVE-2020-36862

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) …

Fix: 5.6.11+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2020-36864

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validati…

Fix: 5.7.2+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2020-36865

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Managem…

Fix: 5.7.2+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2020-36866

Nagios XI versions prior to 5.7.3 are vulnerable to cross-site scripting (XSS) via the Manage Users page of the Admin interface. Insufficient validat…

Fix: 5.7.2+
Fix from $1,600 2025-10-30
Nagios Xi HIGH 8.8
CVE-2020-36856

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient v…

Fix: 5.6.14+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2020-36859

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the objec…

Fix: 5.7.4+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.2
CVE-2020-36857

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires a…

Fix: 5.6.14+
Fix from $1,950 2025-10-30
Log Server MEDIUM 5.4
CVE-2020-36858

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and…

Fix: 2.1.6+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2020-36860

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site scripting (XSS) vulnerabilities…

Fix: 5.7.4+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2020-36861

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site scripting (XSS) vulnerabilities…

Fix: 5.7.5+
Fix from $1,600 2025-10-30
Nagios Xi HIGH 8.8
CVE-2018-25122

Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used uns…

Fix: 5.4.13+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 7.8
CVE-2018-25123

Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts execute…

Fix: 5.5.7+
Fix from $1,950 2025-10-30
Fusion MEDIUM 6.1
CVE-2017-20209

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escapi…

Mitigation only
Fix from $1,600 2025-10-30
Fusion MEDIUM 6.1
CVE-2018-25119

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escap…

Fix: 4.1.5+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2016-15052

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or e…

Fix: 5.2.4+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2016-15053

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient valida…

Fix: 5.2.4+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2018-25121

Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or e…

Fix: 5.4.13+
Fix from $1,600 2025-10-30
Nagios Xi HIGH 8.8
CVE-2013-10073

Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a…

Fix: 2012+
Fix from $1,950 2025-10-30
Nagios Xi HIGH 8.8
CVE-2016-15050

Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters wer…

Fix: 5.2.4+
Fix from $1,950 2025-10-30
Nagios Xi MEDIUM 6.5
CVE-2013-10072

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly rea…

Fix: after 2011
Fix from $1,600 2025-10-30