Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-2041EPSS 73% Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut… Nagios Xi Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-2042EPSS 6% Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c… Nagios Xi Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2026-2043EPSS 73% Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to… Nagios Xi Mitigation only Fix from $1,9502026-02-20 HIGH 8.8 CVE-2025-67255 In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulne… Nagios Xi Mitigation only Fix from $1,9502025-12-29 HIGH 7.5 CVE-2025-67254 NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php. Nagios Xi Mitigation only Fix from $1,9502025-12-29 MEDIUM 6.7 CVE-2025-34288 Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and applicati… Nagios Xi after 2024 Fix from $1,6002025-12-16 HIGH 7.8 CVE-2025-34323 Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-w… Log Server 2026+ Fix from $1,9502025-11-17 HIGH 7.2 CVE-2025-34322EPSS 9% Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries… Log Server 2026+ Fix from $1,9502025-11-17 MEDIUM 6.5 CVE-2024-13998 Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passw… Nagios Xi 2024+ Fix from $1,6002025-11-03 HIGH 7.2 CVE-2024-13997 Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrat… Nagios Xi 2024+ Fix from $1,9502025-11-03 MEDIUM 5.4 CVE-2021-47698 Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escap… Nagios Xi 5.8.7+ Fix from $1,6002025-11-03 MEDIUM 5.4 CVE-2024-13992 Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following… Nagios Xi 2024+ Fix from $1,6002025-10-31 HIGH 8.8 CVE-2025-34298 Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set th… Log Server 2024+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2025-34287 Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but own… Nagios Xi 2024+ Fix from $1,9502025-10-30 CRITICAL 9.8 CVE-2025-34274 Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash proces… Log Server 2024+ Fix from $2,3002025-10-30 CRITICAL 9.8 CVE-2025-34277 Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated … Log Server 2024+ Fix from $2,3002025-10-30 HIGH 8.8 CVE-2025-34284 Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2025-34280 Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate… Network Analyzer 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2025-34286 Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient va… Nagios Xi 2026+ Fix from $1,9502025-10-30 MEDIUM 6.5 CVE-2025-34283 Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated … Nagios Xi 2024+ Fix from $1,6002025-10-30 MEDIUM 5.4 CVE-2025-34278 Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calc… Network Analyzer 2024+ Fix from $1,6002025-10-30 CRITICAL 9.8 CVE-2025-34271 Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from pe… Log Server 2024+ Fix from $2,3002025-10-30 MEDIUM 6.5 CVE-2025-34272 In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back… Log Server 2024+ Fix from $1,6002025-10-30 MEDIUM 6.5 CVE-2025-34273 Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global … Log Server 2024+ Fix from $1,6002025-10-30 HIGH 8.8 CVE-2024-14005 Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input i… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.8 CVE-2024-58273 Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands … Log Server 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2024-14008 Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2024-14009 Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an… Nagios Xi 2024+ Fix from $1,9502025-10-30 HIGH 7.2 CVE-2025-34134 Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficie… Nagios Xi 2024+ Fix from $1,9502025-10-30 MEDIUM 6.1 CVE-2024-14006 Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when … Nagios Xi 2024+ Fix from $1,6002025-10-30