VYPR

Nagios

by Nagios

Source repositories

CVEs (181)

  • CVE-2014-5009CriMar 31, 2017
    risk 0.57cvss 9.8epss 0.05

    Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

  • CVE-2008-7313CriMar 31, 2017
    risk 0.57cvss 9.8epss 0.05

    The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.

  • CVE-2020-35578HigJan 13, 2021
    risk 0.56cvss 7.2epss 0.82

    An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.

  • CVE-2016-9566HigDec 15, 2016
    risk 0.54cvss 7.8epss 0.05

    base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

  • CVE-2021-40344HigOct 26, 2021
    risk 0.52cvss 7.2epss 0.65

    An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote…

  • CVE-2021-47700HigOct 30, 2025
    risk 0.51cvss 7.8epss 0.00

    Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and…

  • CVE-2021-40343HigOct 26, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.

  • CVE-2021-37349HigAug 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.

  • CVE-2021-37345HigAug 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

  • CVE-2021-3277HigJun 7, 2021
    risk 0.51cvss 7.2epss 0.55

    Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

  • CVE-2019-9166HigMar 28, 2019
    risk 0.51cvss 7.8epss 0.01

    Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.

  • CVE-2018-10736HigMay 16, 2018
    risk 0.50cvss 7.2epss 0.42

    A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

  • CVE-2026-48554HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or…

  • CVE-2021-37348HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.03

    Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

  • CVE-2025-34286HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administrator to inject shell…

  • CVE-2025-34134HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled BPI configuration parameters (notably bpi_logfile and bpi_configfile)…

  • CVE-2023-40934HigSep 19, 2023
    risk 0.47cvss 7.2epss 0.02

    A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

  • CVE-2021-3273HigFeb 25, 2021
    risk 0.47cvss 7.2epss 0.07

    Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.

  • CVE-2021-25299MedFeb 15, 2021
    risk 0.47cvss 6.1epss 0.98

    Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to…

  • CVE-2025-34288MedDec 16, 2025
    risk 0.44cvss 6.7epss 0.02

    Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file…

Page 4 of 10