Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-37350EPSS 79% Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation. Nagios Xi 5.8.5+ Fix from $2,3002021-08-13 CRITICAL 9.8 CVE-2021-37353 Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php. Nagios Xi Docker Wizard 1.1.3+ Fix from $2,3002021-08-13 HIGH 7.8 CVE-2021-37345 Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scrip… Nagios Xi 5.8.5+ Fix from $1,9502021-08-13 HIGH 7.8 CVE-2021-37347 Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as … Nagios Xi 5.8.5+ Fix from $1,9502021-08-13 HIGH 7.8 CVE-2021-37349 Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database. Nagios Xi 5.8.5+ Fix from $1,9502021-08-13 HIGH 7.5 CVE-2021-37348 Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php. Nagios Xi 5.8.5+ Fix from $1,9502021-08-13 MEDIUM 6.1 CVE-2021-37352EPSS 6% An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could … Nagios Xi 5.8.5+ Fix from $1,6002021-08-13 MEDIUM 5.3 CVE-2021-37351 Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP … Nagios Xi 5.8.5+ Fix from $1,6002021-08-13 HIGH 8.8 CVE-2021-37343EPSS 24% A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under securit… Nagios Xi 5.8.5+ Fix from $1,9502021-08-13 MEDIUM 5.4 CVE-2021-35478EPSS 77% Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filte… Log Server 2.1.9+ Fix from $1,6002021-07-30 MEDIUM 5.4 CVE-2021-35479EPSS 13% Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp par… Log Server 2.1.9+ Fix from $1,6002021-07-30 HIGH 7.2 CVE-2021-3277EPSS 55% Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-in… Nagios Xi after 5.7.5 Fix from $1,9502021-06-07 CRITICAL 9.8 CVE-2020-28907 Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors rel… Fusion after 4.1.8 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28908EPSS 6% Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios. Fusion after 4.1.8 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28910 Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, … Nagios Xi after 5.7.5 Fix from $2,3002021-05-24 HIGH 8.8 CVE-2020-28906 Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged… Fusion after 5.7.5 Fix from $1,9502021-05-24 HIGH 8.8 CVE-2020-28909EPSS 5% Incorrect File Permissions in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root via modification of scripts. Low-privileges use… Fusion after 4.1.8 Fix from $1,9502021-05-24 MEDIUM 6.5 CVE-2020-28911 Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused serve… Fusion after 4.1.8 Fix from $1,6002021-05-24 CRITICAL 9.8 CVE-2020-28900 Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges… Fusion after 5.7.5 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28901EPSS 9% Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt compone… Fusion after 4.1.8 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28902EPSS 6% Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php. Fusion after 4.1.8 Fix from $2,3002021-05-24 CRITICAL 9.8 CVE-2020-28904 Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious co… Fusion after 4.1.8 Fix from $2,3002021-05-24 HIGH 8.8 CVE-2020-28905EPSS 26% Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination. Fusion after 4.1.8 Fix from $1,9502021-05-24 MEDIUM 6.1 CVE-2020-28903EPSS 10% Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka … Fusion after 4.1.8 Fix from $1,6002021-05-24 CRITICAL 9.8 CVE-2021-28925 SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/. Network Analyzer 2.4.3+ Fix from $2,3002021-04-08 MEDIUM 6.1 CVE-2021-28924EPSS 9% Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page. Network Analyzer 2.4.3+ Fix from $1,6002021-04-08 HIGH 7.2 CVE-2021-3273EPSS 7% Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must ha… Nagios Xi 5.7+ Fix from $1,9502021-02-25 HIGH 8.8 CVE-2020-24899EPSS 17% Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp q… Nagios Xi No fix yet Fix from $1,9502021-02-15 HIGH 7.2 CVE-2020-22427EPSS 14% NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a r… Nagios Xi No fix yet Fix from $1,9502021-02-15 HIGH 8.8 CVE-2021-25296 KEVEPSS 72% Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/… Nagios Xi after 5.7.5 Fix from $1,9502021-02-15