Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi HIGH 8.8
CVE-2021-25297 KEVEPSS 56%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Nagios Xi HIGH 8.8
CVE-2021-25298 KEVEPSS 75%

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…

Fix: after 5.7.5
Fix from $1,950 2021-02-15
Nagios Xi MEDIUM 6.1
CVE-2021-25299EPSS 98%

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php…

No fix yet
Fix from $1,600 2021-02-15
Favorites MEDIUM 5.3
CVE-2021-26024EPSS 19%

The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for an…

Fix: 1.0.2+
Fix from $1,600 2021-02-03
Favorites MEDIUM 6.1
CVE-2021-26023EPSS 25%

The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.

Fix: 1.0.2+
Fix from $1,600 2021-02-03
Nagios Xi CRITICAL 9.8
CVE-2021-3193EPSS 10%

Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated a…

Fix: after 5.7.0
Fix from $2,300 2021-01-26
Log Server MEDIUM 6.1
CVE-2020-25385EPSS 16%

Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name p…

Fix: after 2.1.7
Fix from $1,600 2021-01-20
Nagios Xi HIGH 7.2
CVE-2020-35578EPSS 82%

An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugi…

Fix: 5.8.0+
Fix from $1,950 2021-01-13
Nagios Core HIGH 8.8
CVE-2020-35269

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for host…

Mitigation only
Fix from $1,950 2020-12-23
Nagios Xi MEDIUM 5.4
CVE-2020-27990EPSS 34%

Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).

Fix: 5.7.5+
Fix from $1,600 2020-11-16
Nagios Xi MEDIUM 5.4
CVE-2020-27991EPSS 34%

Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).

Fix: 5.7.5+
Fix from $1,600 2020-11-16
Nagios Xi MEDIUM 5.4
CVE-2020-27988EPSS 91%

Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

Fix: 5.7.5+
Fix from $1,600 2020-11-16
Nagios Xi MEDIUM 5.4
CVE-2020-27989EPSS 34%

Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).

Fix: 5.7.5+
Fix from $1,600 2020-11-16
Nagios Xi HIGH 8.8
CVE-2020-28648EPSS 6%

Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.

Fix: 5.7.5+
Fix from $1,950 2020-11-16
Nagios Xi HIGH 7.8
CVE-2020-5796

Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, result…

No fix yet
Fix from $1,950 2020-11-13
Nagios Xi HIGH 7.2
CVE-2020-5791EPSS 79%

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating s…

Fix: after 5.7.3
Fix from $1,950 2020-10-20
Nagios Xi HIGH 7.2
CVE-2020-5792EPSS 61%

Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files …

No fix yet
Fix from $1,950 2020-10-20
Nagios Xi MEDIUM 6.5
CVE-2020-5790

Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into cli…

No fix yet
Fix from $1,600 2020-10-20
Nagios Xi CRITICAL 9.8
CVE-2020-15903

An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included f…

Fix: 5.7.3+
Fix from $2,300 2020-09-09
Log Server MEDIUM 5.4
CVE-2020-16157EPSS 14%

A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.

Fix: 2.1.7+
Fix from $1,600 2020-07-30
Nagios Xi HIGH 8.8
CVE-2020-15901EPSS 22%

In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.

Fix: 5.7.2+
Fix from $1,950 2020-07-22
Nagios Xi MEDIUM 6.1
CVE-2020-15902EPSS 35%

Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.

Fix: 5.7.2+
Fix from $1,600 2020-07-22
Nagios HIGH 8.8
CVE-2020-6585

Nagios Log Server 2.1.3 has CSRF.

No fix yet
Fix from $1,950 2020-03-16
Nagios MEDIUM 6.5
CVE-2020-6584

Nagios Log Server 2.1.3 has Incorrect Access Control.

No fix yet
Fix from $1,600 2020-03-16
Nagios MEDIUM 5.4
CVE-2020-6586EPSS 19%

Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious …

Mitigation only
Fix from $1,600 2020-03-16
Nagios HIGH 7.0
CVE-2019-3698

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Ser…

Fix: 3.0.6 / 3.5.1+
Fix from $1,950 2020-02-28
Nagios Xi HIGH 8.8
CVE-2019-20197EPSS 22%

In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php…

No fix yet
Fix from $1,950 2019-12-31
Nagios Xi MEDIUM 5.4
CVE-2019-20139EPSS 26%

In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency param…

No fix yet
Fix from $1,600 2019-12-30
Nagios Xi HIGH 8.8
CVE-2019-15949 KEVEPSS 77%

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin …

Fix: 5.6.6+
Fix from $1,950 2019-09-05
Log Server MEDIUM 6.1
CVE-2019-15898

Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.

Fix: 2.0.8+
Fix from $1,600 2019-09-03