VYPR

Nagios

by Nagios

Source repositories

CVEs (169)

  • CVE-2021-37349HigAug 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.

  • CVE-2021-37345HigAug 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

  • CVE-2021-3277HigJun 7, 2021
    risk 0.51cvss 7.2epss 0.55

    Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.

  • CVE-2019-9166HigMar 28, 2019
    risk 0.51cvss 7.8epss 0.01

    Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.

  • CVE-2016-10089HigFeb 15, 2017
    risk 0.51cvss 7.8epss 0.01

    Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

  • CVE-2018-10736HigMay 16, 2018
    risk 0.50cvss 7.2epss 0.43

    A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.

  • CVE-2026-48553HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a…

  • CVE-2021-37348HigAug 13, 2021
    risk 0.49cvss 7.5epss 0.03

    Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.

  • CVE-2025-34286HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administrator to inject shell…

  • CVE-2025-34134HigOct 30, 2025
    risk 0.47cvss 7.2epss 0.02

    Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled BPI configuration parameters (notably bpi_logfile and bpi_configfile)…

  • CVE-2023-40934HigSep 19, 2023
    risk 0.47cvss 7.2epss 0.03

    A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.

  • CVE-2021-3273HigFeb 25, 2021
    risk 0.47cvss 7.2epss 0.07

    Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.

  • CVE-2021-25299MedFeb 15, 2021
    risk 0.47cvss 6.1epss 0.98

    Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to…

  • CVE-2025-34288MedDec 16, 2025
    risk 0.44cvss 6.7epss 0.02

    Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file…

  • CVE-2018-15712MedNov 14, 2018
    risk 0.44cvss 6.1epss 0.49

    Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

  • CVE-2023-40931MedSep 19, 2023
    risk 0.43cvss 6.5epss 0.11

    A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

  • CVE-2020-6584MedMar 16, 2020
    risk 0.43cvss 6.5epss 0.04

    Nagios Log Server 2.1.3 has Incorrect Access Control.

  • CVE-2025-34283MedOct 30, 2025
    risk 0.42cvss 6.5epss 0.01

    Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.

  • CVE-2024-54961MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.02

    Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.

  • CVE-2024-54960MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

Page 4 of 9