Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi CRITICAL 9.8
CVE-2018-17148

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios…

Fix: 5.5.4+
Fix from $2,300 2019-06-19
Nagios Xi MEDIUM 5.4
CVE-2018-17146

A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of t…

Fix: 5.5.4+
Fix from $1,600 2019-06-19
Nagios Xi CRITICAL 9.8
CVE-2019-12279

Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this…

No fix yet
Fix from $2,300 2019-05-22
Nagios Xi HIGH 7.8
CVE-2019-9166

Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xi…

Fix: 5.5.11+
Fix from $1,950 2019-03-28
Nagios Xi MEDIUM 6.1
CVE-2019-9167EPSS 22%

Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow paramete…

Fix: 5.5.11+
Fix from $1,600 2019-03-28
Nagios Xi CRITICAL 9.8
CVE-2019-9165EPSS 5%

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicio…

Fix: 5.5.11+
Fix from $2,300 2019-03-28
Incident Manager CRITICAL 9.8
CVE-2019-9203EPSS 20%

Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.

Fix: 2.2.7+
Fix from $2,300 2019-03-28
Incident Manager CRITICAL 9.8
CVE-2019-9204EPSS 20%

SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.

Fix: 2.2.7+
Fix from $2,300 2019-03-28
Incident Manager HIGH 8.8
CVE-2019-9202EPSS 24%

Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.

Fix: 2.2.7+
Fix from $1,950 2019-03-28
Nagios Xi HIGH 8.8
CVE-2019-9164EPSS 46%

Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.

Fix: 5.5.11+
Fix from $1,950 2019-03-28
Nagios Xi MEDIUM 6.1
CVE-2018-20171

An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in…

Fix: 5.5.8+
Fix from $1,600 2018-12-17
Nagios Xi MEDIUM 6.1
CVE-2018-20172

An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, result…

Fix: 5.5.8+
Fix from $1,600 2018-12-17
Nagios Xi CRITICAL 9.8
CVE-2018-15708EPSS 89%

Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

No fix yet
Fix from $2,300 2018-11-14
Nagios Xi HIGH 8.8
CVE-2018-15709EPSS 21%

Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.

No fix yet
Fix from $1,950 2018-11-14
Nagios Xi HIGH 8.8
CVE-2018-15711EPSS 36%

Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new…

No fix yet
Fix from $1,950 2018-11-14
Nagios Xi HIGH 7.8
CVE-2018-15710EPSS 44%

Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.

No fix yet
Fix from $1,950 2018-11-14
Nagios Xi MEDIUM 6.1
CVE-2018-15712EPSS 49%

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

No fix yet
Fix from $1,600 2018-11-14
Nagios Xi MEDIUM 6.1
CVE-2018-15714

Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.

No fix yet
Fix from $1,600 2018-11-14
Nagios Xi MEDIUM 5.4
CVE-2018-15713EPSS 7%

Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.

No fix yet
Fix from $1,600 2018-11-14
Nagios HIGH 7.8
CVE-2016-8641

A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing th…

Patch available
Fix from $1,950 2018-08-01
Nagios MEDIUM 5.5
CVE-2018-13441

qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-…

Fix: after 4.4.1
Fix from $1,600 2018-07-12
Nagios Core MEDIUM 5.5
CVE-2018-13457

qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-serv…

Fix: after 4.4.1
Fix from $1,600 2018-07-12
Nagios Core MEDIUM 5.5
CVE-2018-13458

qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-serv…

Fix: after 4.4.1
Fix from $1,600 2018-07-12
Fusion MEDIUM 6.1
CVE-2018-12501

Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.

Fix: 4.1.4+
Fix from $1,600 2018-06-16
Nagios Xi HIGH 7.2
CVE-2018-10735EPSS 43%

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.

Fix: 5.4.13+
Fix from $1,950 2018-05-16
Nagios Xi HIGH 7.2
CVE-2018-10736EPSS 43%

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

Fix: 5.4.13+
Fix from $1,950 2018-05-16
Nagios Xi HIGH 7.2
CVE-2018-10737EPSS 43%

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.

Fix: 5.4.13+
Fix from $1,950 2018-05-16
Nagios Xi HIGH 7.2
CVE-2018-10738EPSS 43%

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.

Fix: 5.4.13+
Fix from $1,950 2018-05-16
Nagios Xi MEDIUM 6.5
CVE-2018-10553EPSS 39%

An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginn…

Mitigation only
Fix from $1,600 2018-04-30
Nagios Xi MEDIUM 5.4
CVE-2018-10554

An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm pa…

No fix yet
Fix from $1,600 2018-04-30