Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi CRITICAL 9.8
CVE-2021-37350EPSS 79%

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

Fix: 5.8.5+
Fix from $2,300 2021-08-13
Nagios Xi Docker Wizard CRITICAL 9.8
CVE-2021-37353

Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.

Fix: 1.1.3+
Fix from $2,300 2021-08-13
Nagios Xi HIGH 7.8
CVE-2021-37345

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scrip…

Fix: 5.8.5+
Fix from $1,950 2021-08-13
Nagios Xi HIGH 7.8
CVE-2021-37347

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as …

Fix: 5.8.5+
Fix from $1,950 2021-08-13
Nagios Xi HIGH 7.8
CVE-2021-37349

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.

Fix: 5.8.5+
Fix from $1,950 2021-08-13
Nagios Xi HIGH 7.5
CVE-2021-37348

Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

Fix: 5.8.5+
Fix from $1,950 2021-08-13
Nagios Xi MEDIUM 6.1
CVE-2021-37352EPSS 6%

An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could …

Fix: 5.8.5+
Fix from $1,600 2021-08-13
Nagios Xi MEDIUM 5.3
CVE-2021-37351

Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP …

Fix: 5.8.5+
Fix from $1,600 2021-08-13
Nagios Xi HIGH 8.8
CVE-2021-37343EPSS 24%

A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under securit…

Fix: 5.8.5+
Fix from $1,950 2021-08-13
Log Server MEDIUM 5.4
CVE-2021-35478EPSS 77%

Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filte…

Fix: 2.1.9+
Fix from $1,600 2021-07-30
Log Server MEDIUM 5.4
CVE-2021-35479EPSS 13%

Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp par…

Fix: 2.1.9+
Fix from $1,600 2021-07-30
Nagios Xi HIGH 7.2
CVE-2021-3277EPSS 55%

Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-in…

Fix: after 5.7.5
Fix from $1,950 2021-06-07
Fusion CRITICAL 9.8
CVE-2020-28907

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors rel…

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28908EPSS 6%

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Nagios Xi CRITICAL 9.8
CVE-2020-28910

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, …

Fix: after 5.7.5
Fix from $2,300 2021-05-24
Fusion HIGH 8.8
CVE-2020-28906

Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged…

Fix: after 5.7.5
Fix from $1,950 2021-05-24
Fusion HIGH 8.8
CVE-2020-28909EPSS 5%

Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges use…

Fix: after 4.1.8
Fix from $1,950 2021-05-24
Fusion MEDIUM 6.5
CVE-2020-28911

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused serve…

Fix: after 4.1.8
Fix from $1,600 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28900

Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges…

Fix: after 5.7.5
Fix from $2,300 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28901EPSS 9%

Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt compone…

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28902EPSS 6%

Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Fusion CRITICAL 9.8
CVE-2020-28904

Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious co…

Fix: after 4.1.8
Fix from $2,300 2021-05-24
Fusion HIGH 8.8
CVE-2020-28905EPSS 26%

Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.

Fix: after 4.1.8
Fix from $1,950 2021-05-24
Fusion MEDIUM 6.1
CVE-2020-28903EPSS 10%

Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka …

Fix: after 4.1.8
Fix from $1,600 2021-05-24
Network Analyzer CRITICAL 9.8
CVE-2021-28925

SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

Fix: 2.4.3+
Fix from $2,300 2021-04-08
Network Analyzer MEDIUM 6.1
CVE-2021-28924EPSS 9%

Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.

Fix: 2.4.3+
Fix from $1,600 2021-04-08
Nagios Xi HIGH 7.2
CVE-2021-3273EPSS 7%

Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must ha…

Fix: 5.7+
Fix from $1,950 2021-02-25
Nagios Xi HIGH 8.8
CVE-2020-24899EPSS 17%

Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp q…

No fix yet
Fix from $1,950 2021-02-15
Nagios Xi HIGH 7.2
CVE-2020-22427EPSS 14%

NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a r…

No fix yet
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2021-25296 KEVEPSS 72%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15