VYPR

Nagios

by Nagios

Source repositories

CVEs (169)

  • CVE-2021-25296HigKEVFeb 15, 2021
    risk 0.78cvss 8.8epss 0.72

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which…

  • CVE-2021-25297HigKEVFeb 15, 2021
    risk 0.77cvss 8.8epss 0.56

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead…

  • CVE-2018-15708CriNov 14, 2018
    risk 0.74cvss 9.8epss 0.89

    Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2018-8734CriApr 18, 2018
    risk 0.71cvss 9.8epss 0.53

    SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

  • CVE-2023-48085CriDec 14, 2023
    risk 0.70cvss 9.8epss 0.76

    Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

  • CVE-2021-37350CriAug 13, 2021
    risk 0.70cvss 9.8epss 0.79

    Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

  • CVE-2021-37346CriAug 13, 2021
    risk 0.70cvss 9.8epss 0.74

    Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).

  • CVE-2018-8733CriApr 18, 2018
    risk 0.69cvss 9.8epss 0.28

    Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

  • CVE-2016-9565CriDec 15, 2016
    risk 0.69cvss 9.8epss 0.23

    MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2023-48084CriDec 14, 2023
    risk 0.66cvss 9.8epss 0.34

    Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

  • CVE-2019-9204CriMar 28, 2019
    risk 0.65cvss 9.8epss 0.20

    SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.

  • CVE-2019-9203CriMar 28, 2019
    risk 0.65cvss 9.8epss 0.20

    Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.

  • CVE-2018-8735HigApr 18, 2018
    risk 0.65cvss 8.8epss 0.64

    Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

  • CVE-2024-13999CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of…

  • CVE-2024-13996CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This…

  • CVE-2024-13994CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized…

  • CVE-2012-10063CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to…

  • CVE-2024-33775CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

  • CVE-2022-38250CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.03

    Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

  • CVE-2020-28910CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.04

    Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

Page 1 of 9