Nagios
by Nagios
Source repositories
CVEs (181)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36365 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh. | ||
| CVE-2021-36364 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards. | ||
| CVE-2021-36363 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php. | ||
| CVE-2020-28910 | Cri | 0.64 | 9.8 | 0.04 | May 24, 2021 | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh. | ||
| CVE-2021-3193 | Cri | 0.64 | 9.8 | 0.10 | Jan 26, 2021 | Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user. | ||
| CVE-2020-15903 | Cri | 0.64 | 9.8 | 0.05 | Sep 9, 2020 | An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3. | ||
| CVE-2019-9165 | Cri | 0.64 | 9.8 | 0.05 | Mar 28, 2019 | SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id. | ||
| CVE-2018-8736 | Hig | 0.64 | 8.8 | 0.46 | Apr 18, 2018 | A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root. | ||
| CVE-2016-0726 | Cri | 0.64 | 9.8 | 0.02 | Jun 6, 2017 | The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials. | ||
| CVE-2026-2043 | Hig | 0.63 | 8.8 | 0.74 | Feb 20, 2026 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The… | ||
| CVE-2026-2041 | Hig | 0.63 | 8.8 | 0.74 | Feb 20, 2026 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific… | ||
| CVE-2021-37343 | Hig | 0.62 | 8.8 | 0.24 | Aug 13, 2021 | A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios. | ||
| CVE-2019-9164 | Hig | 0.61 | 8.8 | 0.46 | Mar 28, 2019 | Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job. | ||
| CVE-2018-15711 | Hig | 0.60 | 8.8 | 0.36 | Nov 14, 2018 | Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges. | ||
| CVE-2025-34227 | Hig | 0.59 | 8.8 | 0.24 | Sep 25, 2025 | Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute… | ||
| CVE-2012-10029 | Hig | 0.59 | — | 0.03 | Aug 5, 2025 | Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution. | ||
| CVE-2020-15901 | Hig | 0.59 | 8.8 | 0.22 | Jul 22, 2020 | In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys. | ||
| CVE-2019-20197 | Hig | 0.59 | 8.8 | 0.22 | Dec 31, 2019 | In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account. | ||
| CVE-2019-9202 | Hig | 0.59 | 8.8 | 0.24 | Mar 28, 2019 | Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues. | ||
| CVE-2018-15709 | Hig | 0.59 | 8.8 | 0.21 | Nov 14, 2018 | Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request. |
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
- risk 0.64cvss 9.8epss 0.04
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.
- risk 0.64cvss 9.8epss 0.10
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
- risk 0.64cvss 9.8epss 0.05
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
- risk 0.64cvss 8.8epss 0.46
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.
- risk 0.64cvss 9.8epss 0.02
The Fedora Nagios package uses "nagiosadmin" as the default password for the "nagiosadmin" administrator account, which makes it easier for remote attackers to obtain access by leveraging knowledge of the credentials.
- risk 0.63cvss 8.8epss 0.74
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The…
- risk 0.63cvss 8.8epss 0.74
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific…
- risk 0.62cvss 8.8epss 0.24
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
- risk 0.61cvss 8.8epss 0.46
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
- risk 0.60cvss 8.8epss 0.36
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
- risk 0.59cvss 8.8epss 0.24
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute…
- risk 0.59cvss —epss 0.03
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.
- risk 0.59cvss 8.8epss 0.22
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
- risk 0.59cvss 8.8epss 0.22
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
- risk 0.59cvss 8.8epss 0.24
Nagios IM (component of Nagios XI) before 2.2.7 allows authenticated users to execute arbitrary code via API key issues.
- risk 0.59cvss 8.8epss 0.21
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
Page 2 of 10