Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Nagios Subscribe
Total 164 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-3273 1 Nagios 1 Nagios Xi 2021-03-02 9.0 HIGH 7.2 HIGH
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.
CVE-2021-26024 1 Nagios 2 Favorites, Nagios Xi 2021-02-05 5.0 MEDIUM 5.3 MEDIUM
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
CVE-2021-26023 1 Nagios 2 Favorites, Nagios Xi 2021-02-05 4.3 MEDIUM 6.1 MEDIUM
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
CVE-2021-3193 1 Nagios 1 Nagios Xi 2021-02-03 7.5 HIGH 9.8 CRITICAL
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
CVE-2020-25385 1 Nagios 1 Log Server 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
CVE-2020-5796 1 Nagios 1 Nagios Xi 2020-11-24 7.2 HIGH 7.8 HIGH
Improper preservation of permissions in Nagios XI 5.7.4 allows a local, low-privileged, authenticated user to weaken the permissions of files, resulting in low-privileged users being able to write to and execute arbitrary PHP code with root privileges.
CVE-2020-27988 1 Nagios 1 Nagios Xi 2020-11-17 3.5 LOW 5.4 MEDIUM
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
CVE-2020-27989 1 Nagios 1 Nagios Xi 2020-11-17 3.5 LOW 5.4 MEDIUM
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
CVE-2020-27990 1 Nagios 1 Nagios Xi 2020-11-17 3.5 LOW 5.4 MEDIUM
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
CVE-2020-27991 1 Nagios 1 Nagios Xi 2020-11-17 3.5 LOW 5.4 MEDIUM
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
CVE-2020-15902 1 Nagios 1 Nagios Xi 2020-11-13 4.3 MEDIUM 6.1 MEDIUM
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
CVE-2020-5790 1 Nagios 1 Nagios Xi 2020-10-21 4.3 MEDIUM 6.5 MEDIUM
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
CVE-2018-10554 1 Nagios 1 Nagios Xi 2020-08-24 3.5 LOW 5.4 MEDIUM
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages function; (3) the ajaxhelper.php opts or background parameter; (4) the i[] array parameter to ajax_handler.php; or (5) the deploynotification.php title parameter.
CVE-2018-18245 2 Debian, Nagios 2 Debian Linux, Nagios Core 2020-04-11 3.5 LOW 5.4 MEDIUM
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
CVE-2018-13441 1 Nagios 1 Nagios 2020-04-11 2.1 LOW 5.5 MEDIUM
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
CVE-2018-13457 1 Nagios 1 Nagios Core 2020-04-11 4.3 MEDIUM 5.5 MEDIUM
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
CVE-2018-13458 1 Nagios 1 Nagios Core 2020-04-11 4.3 MEDIUM 5.5 MEDIUM
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
CVE-2020-10820 1 Nagios 1 Nagios Xi 2020-03-23 3.5 LOW 4.8 MEDIUM
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
CVE-2020-10821 1 Nagios 1 Nagios Xi 2020-03-23 3.5 LOW 4.8 MEDIUM
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
CVE-2020-10819 1 Nagios 1 Nagios Xi 2020-03-23 3.5 LOW 4.8 MEDIUM
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.