Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2013-10071
Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. I…
Nagios Xi
after 2011
MEDIUM 5.4
CVE-2013-10074
Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or…
Nagios Xi
2012+
MEDIUM 5.4
CVE-2016-15049
Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Lo…
Log Server
1.4.2+
MEDIUM 5.4
CVE-2016-15051
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddat…
Nagios Xi
5.2.4+
CRITICAL 9.8
CVE-2012-10063
Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated us…
Nagios Xi
after 2011
MEDIUM 5.4
CVE-2011-10036
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient…
Nagios Xi
after 2009
MEDIUM 5.4
CVE-2011-10037
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in …
Nagios Xi
after 2009
MEDIUM 5.4
CVE-2011-10038
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficien…
Nagios Xi
after 2009
MEDIUM 5.4
CVE-2011-10039
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the we…
Nagios Xi
after 2009
MEDIUM 5.4
CVE-2011-10040
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. In…
Nagios Xi
after 2009
HIGH 7.0
CVE-2011-10035
Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due t…
Nagios Xi
after 2009
HIGH 8.6
CVE-2025-60425
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allo…
Fusion
Mitigation only
HIGH 7.6
CVE-2025-60424
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a brut…
Fusion
Mitigation only
HIGH 8.8
CVE-2025-44823EPSS 16%
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/sys…
Log Server
2024+
MEDIUM 6.5
CVE-2025-44824
Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/i…
Log Server
2024+
HIGH 8.8
CVE-2025-34227EPSS 24%
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres…
Nagios Xi
after 2026
HIGH 8.8
CVE-2024-13986
Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Cor…
Nagios Xi
2024+
MEDIUM 6.1
CVE-2025-56432
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in t…
Nagios Xi
Mitigation only
HIGH 7.5
CVE-2025-28059
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper sessi…
Network Analyzer
Mitigation only
HIGH 8.3
CVE-2025-29471EPSS 7%
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email …
Log Server
No fix yet
MEDIUM 6.1
CVE-2024-54957
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability al…
Nagios Xi
Mitigation only
MEDIUM 6.5
CVE-2024-54960
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab comp…
Nagios Xi
Mitigation only
MEDIUM 6.5
CVE-2024-54961
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the username…
Nagios Xi
Mitigation only
MEDIUM 6.1
CVE-2024-54958
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject ma…
Nagios Xi
Mitigation only
MEDIUM 6.1
CVE-2024-54959
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scri…
Nagios Xi
Mitigation only
MEDIUM 5.4
CVE-2024-42898
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in…
Nagios Xi
No fix yet
CRITICAL 9.1
CVE-2023-48082
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the sam…
Nagios Xi
2014+
HIGH 7.8
CVE-2024-43199
Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.
Ndoutils
2.1.4+
CRITICAL 9.8
CVE-2024-33775
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
Nagios Xi
No fix yet
CRITICAL 9.8
CVE-2024-24401EPSS 46%
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.p…
Nagios Xi
Mitigation only