Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi MEDIUM 6.1
CVE-2013-10071

Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. I…

Fix: after 2011
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2013-10074

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or…

Fix: 2012+
Fix from $1,600 2025-10-30
Log Server MEDIUM 5.4
CVE-2016-15049

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Lo…

Fix: 1.4.2+
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2016-15051

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddat…

Fix: 5.2.4+
Fix from $1,600 2025-10-30
Nagios Xi CRITICAL 9.8
CVE-2012-10063

Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated us…

Fix: after 2011
Fix from $2,300 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2011-10036

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient…

Fix: after 2009
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2011-10037

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in …

Fix: after 2009
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2011-10038

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficien…

Fix: after 2009
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2011-10039

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the we…

Fix: after 2009
Fix from $1,600 2025-10-30
Nagios Xi MEDIUM 5.4
CVE-2011-10040

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. In…

Fix: after 2009
Fix from $1,600 2025-10-30
Nagios Xi HIGH 7.0
CVE-2011-10035

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due t…

Fix: after 2009
Fix from $1,950 2025-10-30
Fusion HIGH 8.6
CVE-2025-60425

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allo…

Mitigation only
Fix from $1,950 2025-10-27
Fusion HIGH 7.6
CVE-2025-60424

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a brut…

Mitigation only
Fix from $1,950 2025-10-27
Log Server HIGH 8.8
CVE-2025-44823EPSS 16%

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/sys…

Fix: 2024+
Fix from $1,950 2025-10-07
Log Server MEDIUM 6.5
CVE-2025-44824

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/i…

Fix: 2024+
Fix from $1,600 2025-10-07
Nagios Xi HIGH 8.8
CVE-2025-34227EPSS 24%

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres…

Fix: after 2026
Fix from $1,950 2025-09-25
Nagios Xi HIGH 8.8
CVE-2024-13986

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Cor…

Fix: 2024+
Fix from $1,950 2025-08-28
Nagios Xi MEDIUM 6.1
CVE-2025-56432

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in t…

Mitigation only
Fix from $1,600 2025-08-26
Network Analyzer HIGH 7.5
CVE-2025-28059

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper sessi…

Mitigation only
Fix from $1,950 2025-04-18
Log Server HIGH 8.3
CVE-2025-29471EPSS 7%

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email …

No fix yet
Fix from $1,950 2025-04-15
Nagios Xi MEDIUM 6.1
CVE-2024-54957

Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability al…

Mitigation only
Fix from $1,600 2025-02-27
Nagios Xi MEDIUM 6.5
CVE-2024-54960

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab comp…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 6.5
CVE-2024-54961

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the username…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 6.1
CVE-2024-54958

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject ma…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 6.1
CVE-2024-54959

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scri…

Mitigation only
Fix from $1,600 2025-02-20
Nagios Xi MEDIUM 5.4
CVE-2024-42898

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in…

No fix yet
Fix from $1,600 2025-01-09
Nagios Xi CRITICAL 9.1
CVE-2023-48082

Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the sam…

Fix: 2014+
Fix from $2,300 2024-10-14
Ndoutils HIGH 7.8
CVE-2024-43199

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

Fix: 2.1.4+
Fix from $1,950 2024-08-07
Nagios Xi CRITICAL 9.8
CVE-2024-33775

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

No fix yet
Fix from $2,300 2024-05-01
Nagios Xi CRITICAL 9.8
CVE-2024-24401EPSS 46%

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.p…

Mitigation only
Fix from $2,300 2024-02-26