Vulnerability index

Browse CVEs

266 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2018-17148 An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios… Nagios Xi 5.5.4+ Fix from $2,3002019-06-19 MEDIUM 5.4 CVE-2018-17146 A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of t… Nagios Xi 5.5.4+ Fix from $1,6002019-06-19 CRITICAL 9.8 CVE-2019-12279 Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this… Nagios Xi No fix yet Fix from $2,3002019-05-22 HIGH 7.8 CVE-2019-9166 Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xi… Nagios Xi 5.5.11+ Fix from $1,9502019-03-28 MEDIUM 6.1 CVE-2019-9167EPSS 22% Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow paramete… Nagios Xi 5.5.11+ Fix from $1,6002019-03-28 CRITICAL 9.8 CVE-2019-9165EPSS 5% SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicio… Nagios Xi 5.5.11+ Fix from $2,3002019-03-28 CRITICAL 9.8 CVE-2019-9203EPSS 20% Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API. Incident Manager 2.2.7+ Fix from $2,3002019-03-28 CRITICAL 9.8 CVE-2019-9204EPSS 20% SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands. Incident Manager 2.2.7+ Fix from $2,3002019-03-28 HIGH 8.8 CVE-2019-9202EPSS 24% Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues. Incident Manager 2.2.7+ Fix from $1,9502019-03-28 HIGH 8.8 CVE-2019-9164EPSS 46% Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job. Nagios Xi 5.5.11+ Fix from $1,9502019-03-28 MEDIUM 6.1 CVE-2018-20171 An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in… Nagios Xi 5.5.8+ Fix from $1,6002018-12-17 MEDIUM 6.1 CVE-2018-20172 An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, result… Nagios Xi 5.5.8+ Fix from $1,6002018-12-17 CRITICAL 9.8 CVE-2018-15708EPSS 89% Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. Nagios Xi No fix yet Fix from $2,3002018-11-14 HIGH 8.8 CVE-2018-15709EPSS 21% Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request. Nagios Xi No fix yet Fix from $1,9502018-11-14 HIGH 8.8 CVE-2018-15711EPSS 36% Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new… Nagios Xi No fix yet Fix from $1,9502018-11-14 HIGH 7.8 CVE-2018-15710EPSS 44% Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. Nagios Xi No fix yet Fix from $1,9502018-11-14 MEDIUM 6.1 CVE-2018-15712EPSS 49% Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php. Nagios Xi No fix yet Fix from $1,6002018-11-14 MEDIUM 6.1 CVE-2018-15714 Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters. Nagios Xi No fix yet Fix from $1,6002018-11-14 MEDIUM 5.4 CVE-2018-15713EPSS 7% Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php. Nagios Xi No fix yet Fix from $1,6002018-11-14 HIGH 7.8 CVE-2016-8641 A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing th… Nagios Patch available Fix from $1,9502018-08-01 MEDIUM 5.5 CVE-2018-13441 qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-… Nagios after 4.4.1 Fix from $1,6002018-07-12 MEDIUM 5.5 CVE-2018-13457 qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-serv… Nagios Core after 4.4.1 Fix from $1,6002018-07-12 MEDIUM 5.5 CVE-2018-13458 qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-serv… Nagios Core after 4.4.1 Fix from $1,6002018-07-12 MEDIUM 6.1 CVE-2018-12501 Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335. Fusion 4.1.4+ Fix from $1,6002018-06-16 HIGH 7.2 CVE-2018-10735EPSS 43% A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter. Nagios Xi 5.4.13+ Fix from $1,9502018-05-16 HIGH 7.2 CVE-2018-10736EPSS 43% A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter. Nagios Xi 5.4.13+ Fix from $1,9502018-05-16 HIGH 7.2 CVE-2018-10737EPSS 43% A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. Nagios Xi 5.4.13+ Fix from $1,9502018-05-16 HIGH 7.2 CVE-2018-10738EPSS 43% A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter. Nagios Xi 5.4.13+ Fix from $1,9502018-05-16 MEDIUM 6.5 CVE-2018-10553EPSS 39% An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginn… Nagios Xi Mitigation only Fix from $1,6002018-04-30 MEDIUM 5.4 CVE-2018-10554 An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm pa… Nagios Xi No fix yet Fix from $1,6002018-04-30