VYPR

Nagios

by Nagios

Source repositories

CVEs (181)

  • CVE-2018-15712MedNov 14, 2018
    risk 0.44cvss 6.1epss 0.49

    Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

  • CVE-2016-10089HigFeb 15, 2017
    risk 0.44cvss 7.8epss 0.01

    Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

  • CVE-2023-40931MedSep 19, 2023
    risk 0.43cvss 6.5epss 0.12

    A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

  • CVE-2020-6584MedMar 16, 2020
    risk 0.43cvss 6.5epss 0.04

    Nagios Log Server 2.1.3 has Incorrect Access Control.

  • CVE-2025-34283MedOct 30, 2025
    risk 0.42cvss 6.5epss 0.01

    Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.

  • CVE-2024-54961MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.02

    Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.

  • CVE-2024-54960MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

  • CVE-2022-29271MedJun 29, 2022
    risk 0.42cvss 6.5epss 0.02

    In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.

  • CVE-2021-38156MedSep 15, 2021
    risk 0.42cvss 5.4epss 0.93

    In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

  • CVE-2020-27988MedNov 16, 2020
    risk 0.42cvss 5.4epss 0.91

    Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

  • CVE-2020-15902MedJul 22, 2020
    risk 0.42cvss 6.1epss 0.35

    Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.

  • CVE-2019-9167MedMar 28, 2019
    risk 0.41cvss 6.1epss 0.22

    Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.

  • CVE-2017-12847MedAug 23, 2017
    risk 0.41cvss 6.3epss 0.01

    Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a "kill…

  • CVE-2024-13993MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a…

  • CVE-2021-47694MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject…

  • CVE-2020-36862MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch…

  • CVE-2024-54959MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

  • CVE-2024-54958MedFeb 20, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.

  • CVE-2020-23992MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.02

    Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.

  • CVE-2022-38254MedSep 7, 2022
    risk 0.40cvss 6.1epss 0.02

    Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

Page 5 of 10