Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2021-25297 KEVEPSS 56%
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…
Nagios Xi
after 5.7.5
HIGH 8.8
CVE-2021-25298 KEVEPSS 75%
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/…
Nagios Xi
after 5.7.5
MEDIUM 6.1
CVE-2021-25299EPSS 98%
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php…
Nagios Xi
No fix yet
MEDIUM 5.3
CVE-2021-26024EPSS 19%
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for an…
Favorites
1.0.2+
MEDIUM 6.1
CVE-2021-26023EPSS 25%
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
Favorites
1.0.2+
CRITICAL 9.8
CVE-2021-3193EPSS 10%
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated a…
Nagios Xi
after 5.7.0
MEDIUM 6.1
CVE-2020-25385EPSS 16%
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name p…
Log Server
after 2.1.7
HIGH 7.2
CVE-2020-35578EPSS 82%
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugi…
Nagios Xi
5.8.0+
HIGH 8.8
CVE-2020-35269
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for host…
Nagios Core
Mitigation only
MEDIUM 5.4
CVE-2020-27990EPSS 34%
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
Nagios Xi
5.7.5+
MEDIUM 5.4
CVE-2020-27991EPSS 34%
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
Nagios Xi
5.7.5+
MEDIUM 5.4
CVE-2020-27988EPSS 91%
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
Nagios Xi
5.7.5+
MEDIUM 5.4
CVE-2020-27989EPSS 34%
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
Nagios Xi
5.7.5+
HIGH 8.8
CVE-2020-28648EPSS 6%
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
Nagios Xi
5.7.5+
HIGH 7.8
CVE-2020-5796
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, result…
Nagios Xi
No fix yet
HIGH 7.2
CVE-2020-5791EPSS 79%
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating s…
Nagios Xi
after 5.7.3
HIGH 7.2
CVE-2020-5792EPSS 61%
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files …
Nagios Xi
No fix yet
MEDIUM 6.5
CVE-2020-5790
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into cli…
Nagios Xi
No fix yet
CRITICAL 9.8
CVE-2020-15903
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included f…
Nagios Xi
5.7.3+
MEDIUM 5.4
CVE-2020-16157EPSS 14%
A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu.
Log Server
2.1.7+
HIGH 8.8
CVE-2020-15901EPSS 22%
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
Nagios Xi
5.7.2+
MEDIUM 6.1
CVE-2020-15902EPSS 35%
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
Nagios Xi
5.7.2+
HIGH 8.8
CVE-2020-6585
Nagios Log Server 2.1.3 has CSRF.
Nagios
No fix yet
MEDIUM 6.5
CVE-2020-6584
Nagios Log Server 2.1.3 has Incorrect Access Control.
Nagios
No fix yet
MEDIUM 5.4
CVE-2020-6586EPSS 19%
Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious …
Nagios
Mitigation only
HIGH 7.0
CVE-2019-3698
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Ser…
Nagios
3.0.6 / 3.5.1+
HIGH 8.8
CVE-2019-20197EPSS 22%
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php…
Nagios Xi
No fix yet
MEDIUM 5.4
CVE-2019-20139EPSS 26%
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulereport.php hour or frequency param…
Nagios Xi
No fix yet
HIGH 8.8
CVE-2019-15949 KEVEPSS 78%
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin …
Nagios Xi
5.6.6+
MEDIUM 6.1
CVE-2019-15898
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
Log Server
2.0.8+