Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2018-17148
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios…
Nagios Xi
5.5.4+
MEDIUM 5.4
CVE-2018-17146
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of t…
Nagios Xi
5.5.4+
CRITICAL 9.8
CVE-2019-12279
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this…
Nagios Xi
No fix yet
HIGH 7.8
CVE-2019-9166
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xi…
Nagios Xi
5.5.11+
MEDIUM 6.1
CVE-2019-9167EPSS 22%
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow paramete…
Nagios Xi
5.5.11+
CRITICAL 9.8
CVE-2019-9165EPSS 5%
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicio…
Nagios Xi
5.5.11+
CRITICAL 9.8
CVE-2019-9203EPSS 20%
Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
Incident Manager
2.2.7+
CRITICAL 9.8
CVE-2019-9204EPSS 20%
SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.
Incident Manager
2.2.7+
HIGH 8.8
CVE-2019-9202EPSS 24%
Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
Incident Manager
2.2.7+
HIGH 8.8
CVE-2019-9164EPSS 46%
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
Nagios Xi
5.5.11+
MEDIUM 6.1
CVE-2018-20171
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in…
Nagios Xi
5.5.8+
MEDIUM 6.1
CVE-2018-20172
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, result…
Nagios Xi
5.5.8+
CRITICAL 9.8
CVE-2018-15708EPSS 89%
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nagios Xi
No fix yet
HIGH 8.8
CVE-2018-15709EPSS 21%
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nagios Xi
No fix yet
HIGH 8.8
CVE-2018-15711EPSS 36%
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new…
Nagios Xi
No fix yet
HIGH 7.8
CVE-2018-15710EPSS 44%
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
Nagios Xi
No fix yet
MEDIUM 6.1
CVE-2018-15712EPSS 49%
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
Nagios Xi
No fix yet
MEDIUM 6.1
CVE-2018-15714
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
Nagios Xi
No fix yet
MEDIUM 5.4
CVE-2018-15713EPSS 7%
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
Nagios Xi
No fix yet
HIGH 7.8
CVE-2016-8641
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing th…
Nagios
Patch available
MEDIUM 5.5
CVE-2018-13441
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-…
Nagios
after 4.4.1
MEDIUM 5.5
CVE-2018-13457
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-serv…
Nagios Core
after 4.4.1
MEDIUM 5.5
CVE-2018-13458
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-serv…
Nagios Core
after 4.4.1
MEDIUM 6.1
CVE-2018-12501
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
Fusion
4.1.4+
HIGH 7.2
CVE-2018-10735EPSS 43%
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Nagios Xi
5.4.13+
HIGH 7.2
CVE-2018-10736EPSS 43%
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Nagios Xi
5.4.13+
HIGH 7.2
CVE-2018-10737EPSS 43%
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
Nagios Xi
5.4.13+
HIGH 7.2
CVE-2018-10738EPSS 43%
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
Nagios Xi
5.4.13+
MEDIUM 6.5
CVE-2018-10553EPSS 39%
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginn…
Nagios Xi
Mitigation only
MEDIUM 5.4
CVE-2018-10554
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm pa…
Nagios Xi
No fix yet