Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi CRITICAL 9.8
CVE-2024-24402

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

Mitigation only
Fix from $2,300 2024-02-26
Nagios Xi MEDIUM 5.4
CVE-2023-51072

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to…

Fix: 2024+
Fix from $1,600 2024-02-02
Nagios Xi CRITICAL 9.8
CVE-2023-48085EPSS 76%

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

Fix: 5.11.3+
Fix from $2,300 2023-12-14
Nagios Xi CRITICAL 9.8
CVE-2023-48084EPSS 34%

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

Fix: 5.11.3+
Fix from $2,300 2023-12-14
Nagios Xi HIGH 8.8
CVE-2023-40933

A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to exec…

Fix: 5.11.2+
Fix from $1,950 2023-09-19
Nagios Xi HIGH 7.2
CVE-2023-40934

A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Con…

Fix: 5.11.2+
Fix from $1,950 2023-09-19
Nagios Xi MEDIUM 5.4
CVE-2023-40932

A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo compon…

Fix: 5.11.2+
Fix from $1,600 2023-09-19
Nagios Xi MEDIUM 6.5
CVE-2023-40931EPSS 11%

A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL com…

Fix: 5.11.2+
Fix from $1,600 2023-09-19
Nagios Xi MEDIUM 6.1
CVE-2020-23992

Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.

No fix yet
Fix from $1,600 2023-08-22
Nagios Cross Platform Agent MEDIUM 6.1
CVE-2021-4285

A vulnerability classified as problematic was found in Nagios NCPA. This vulnerability affects unknown code of the file agent/listener/templates/tail…

Fix: 2.4.0+
Fix from $1,600 2022-12-27
Nagios Xi CRITICAL 9.8
CVE-2022-38250

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

Mitigation only
Fix from $2,300 2022-09-07
Nagios Xi MEDIUM 6.1
CVE-2022-38248

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

Fix: 5.8.7+
Fix from $1,600 2022-09-07
Nagios Xi MEDIUM 6.1
CVE-2022-38249

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

Mitigation only
Fix from $1,600 2022-09-07
Nagios Xi MEDIUM 6.1
CVE-2022-38254

Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

Fix: 5.8.7+
Fix from $1,600 2022-09-07
Nagios Xi MEDIUM 6.5
CVE-2022-29269

In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/edit…

Fix: after 5.8.5
Fix from $1,600 2022-06-29
Nagios Xi MEDIUM 6.5
CVE-2022-29271

In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This a…

Fix: after 5.8.5
Fix from $1,600 2022-06-29
Nagios Xi MEDIUM 6.1
CVE-2022-29272

In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.

Fix: after 5.8.5
Fix from $1,600 2022-06-29
Nagios Xi HIGH 7.8
CVE-2021-40343

An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileg…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 7.2
CVE-2021-40344EPSS 66%

An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary exten…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi HIGH 7.2
CVE-2021-40345EPSS 23%

An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injec…

No fix yet
Fix from $1,950 2021-10-26
Nagios Xi MEDIUM 6.1
CVE-2021-33179EPSS 12%

The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victi…

Fix: 5.8.4+
Fix from $1,600 2021-10-14
Nagios Xi HIGH 8.8
CVE-2021-33177EPSS 10%

The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor t…

Fix: 5.8.5+
Fix from $1,950 2021-10-14
Nagios Xi MEDIUM 6.5
CVE-2021-37223

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can cr…

Fix: after 5.8.4
Fix from $1,600 2021-10-05
Nagios Xi CRITICAL 9.8
CVE-2021-36363

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

Fix: 5.8.5+
Fix from $2,300 2021-09-28
Nagios Xi CRITICAL 9.8
CVE-2021-36364

Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

Fix: 5.8.5+
Fix from $2,300 2021-09-28
Nagios Xi CRITICAL 9.8
CVE-2021-36365

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

Fix: 5.8.5+
Fix from $2,300 2021-09-28
Nagios Xi CRITICAL 9.8
CVE-2021-36366

Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

Fix: 5.8.5+
Fix from $2,300 2021-09-28
Nagios Xi MEDIUM 5.4
CVE-2021-38156EPSS 89%

In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

Fix: 5.8.6+
Fix from $1,600 2021-09-15
Nagios Xi Switch Wizard CRITICAL 9.8
CVE-2021-37344EPSS 97%

Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS…

Fix: 2.5.7+
Fix from $2,300 2021-08-13
Nagios Xi Watchguard Wizard CRITICAL 9.8
CVE-2021-37346EPSS 74%

Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in a…

Fix: 1.4.8+
Fix from $2,300 2021-08-13