Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nagios Xi CRITICAL 9.8
CVE-2018-8733EPSS 28%

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to m…

Fix: 5.4.13+
Fix from $2,300 2018-04-18
Nagios Xi CRITICAL 9.8
CVE-2018-8734EPSS 53%

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL com…

Fix: 5.4.13+
Fix from $2,300 2018-04-18
Nagios Xi HIGH 8.8
CVE-2018-8735EPSS 64%

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the t…

Fix: 5.4.13+
Fix from $1,950 2018-04-18
Nagios Xi HIGH 8.8
CVE-2018-8736EPSS 47%

A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to…

Fix: 5.4.13+
Fix from $1,950 2018-04-18
Business Process Intelligence MEDIUM 6.1
CVE-2015-3618

Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web s…

Fix: 2.3.4+
Fix from $1,600 2018-02-06
Nagios Core HIGH 7.8
CVE-2017-14312

Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root ac…

Fix: after 4.3.4
Fix from $1,950 2017-09-11
Nagios MEDIUM 6.3
CVE-2017-12847

Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitr…

Fix: after 4.3.2
Fix from $1,600 2017-08-23
Nagios CRITICAL 9.8
CVE-2016-0726

The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote at…

Mitigation only
Fix from $2,300 2017-06-06
Nagios MEDIUM 6.1
CVE-2016-6209

Cross-site scripting (XSS) vulnerability in Nagios.

No fix yet
Fix from $1,600 2017-03-31
Nagios HIGH 7.8
CVE-2016-10089

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

Fix: after 4.2.4
Fix from $1,950 2017-02-15
Nagios CRITICAL 9.8
CVE-2016-9565EPSS 23%

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofin…

Fix: after 4.2.1
Fix from $2,300 2016-12-15
Nagios HIGH 7.8
CVE-2016-9566

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink att…

Fix: after 4.2.3
Fix from $1,950 2016-12-15
Remote Plugin Executor HIGH 7.5
CVE-2014-2913EPSS 15%

Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary co…

Fix: after 2.15
Fix from $1,950 2014-05-07
Nagios MEDIUM 6.4
CVE-2013-7205

Off-by-one error in the process_cgivars function in contrib/daemonchk.c in Nagios Core 3.5.1, 4.0.2, and earlier allows remote authenticated users to…

Fix: after 4.0.2
Fix from $1,600 2014-01-15
Nagios MEDIUM 5.5
CVE-2013-7108EPSS 60%

Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote a…

Fix: after 4.0.2
Fix from $1,600 2014-01-15
Nagios Xi HIGH 7.5
CVE-2013-6875

SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execut…

Fix: after 2012r2.3
Fix from $1,950 2013-11-26
Nagios HIGH 7.5
CVE-2012-6096EPSS 66%

Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x be…

Fix: after 3.4.3
Fix from $1,950 2013-01-22
Nagios HIGH 7.5
CVE-2009-2288EPSS 83%

statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute…

Fix: after 3.1.0
Fix from $1,950 2009-07-01
Nagios MEDIUM 5.0
CVE-2008-6373

Unspecified vulnerability in Nagios before 3.0.6 has unspecified impact and remote attack vectors related to CGI programs, "adaptive external command…

Fix: after 3.0.5
Fix from $1,600 2009-03-02
Nagios MEDIUM 6.8
CVE-2008-5028

Cross-site request forgery (CSRF) vulnerability in cmd.cgi in (1) Nagios 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote attackers to send comma…

Fix: after 4.0.0
Fix from $1,600 2008-11-10
Nagios MEDIUM 6.5
CVE-2008-5027EPSS 7%

The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and …

Fix: after 4.0.0
Fix from $1,600 2008-11-10
Plugins MEDIUM 5.0
CVE-2007-5623

Buffer overflow in the check_snmp function in Nagios Plugins (nagios-plugins) 1.4.10 allows remote attackers to cause a denial of service (crash) via…

Mitigation only
Fix from $1,600 2007-10-23
Plugins MEDIUM 6.8
CVE-2007-5198EPSS 8%

Buffer overflow in the redir function in check_http.c in Nagios Plugins before 1.4.10, when running with the -f (follow) option, allows remote web se…

Fix: after 1.4.9
Fix from $1,600 2007-10-04
Nagios HIGH 7.5
CVE-2006-2489EPSS 5%

Integer overflow in CGI scripts in Nagios 1.x before 1.4.1 and 2.x before 2.3.1 allows remote attackers to cause a denial of service (crash) and poss…

Patch available
Fix from $1,950 2006-05-19
Nagios MEDIUM 5.0
CVE-2006-2162

Buffer overflow in CGI scripts in Nagios 1.x before 1.4 and 2.x before 2.3 allows remote attackers to execute arbitrary code via a negative content l…

Fix: after 2.2
Fix from $1,600 2006-05-03
Nagios HIGH 10.0
CVE-2002-1959

Nagios 1.0b1 through 1.0b3 allows remote attackers to execute arbitrary commands via shell metacharacters in plugin output.

Patch available
Fix from $1,950 2002-12-31