Nagios
by Nagios
Source repositories
CVEs (169)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29271 | Med | 0.42 | 6.5 | 0.02 | Jun 29, 2022 | In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks. | ||
| CVE-2020-15902 | Med | 0.42 | 6.1 | 0.35 | Jul 22, 2020 | Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option. | ||
| CVE-2019-9167 | Med | 0.41 | 6.1 | 0.22 | Mar 28, 2019 | Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter. | ||
| CVE-2017-12847 | Med | 0.41 | 6.3 | 0.01 | Aug 23, 2017 | Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a "kill… | ||
| CVE-2024-13993 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a… | ||
| CVE-2021-47694 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject… | ||
| CVE-2020-36862 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch… | ||
| CVE-2024-54959 | Med | 0.40 | 6.1 | 0.01 | Feb 20, 2025 | Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS). | ||
| CVE-2024-54958 | Med | 0.40 | 6.1 | 0.01 | Feb 20, 2025 | Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page. | ||
| CVE-2020-23992 | Med | 0.40 | 6.1 | 0.02 | Aug 22, 2023 | Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request. | ||
| CVE-2022-38254 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5. | ||
| CVE-2022-38249 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4. | ||
| CVE-2022-38248 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. | ||
| CVE-2022-29272 | Med | 0.40 | 6.1 | 0.04 | Jun 29, 2022 | In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing. | ||
| CVE-2021-33179 | Med | 0.40 | 6.1 | 0.12 | Oct 14, 2021 | The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload. | ||
| CVE-2021-37352 | Med | 0.40 | 6.1 | 0.06 | Aug 13, 2021 | An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link. | ||
| CVE-2018-20172 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-20171 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-15714 | Med | 0.40 | 6.1 | 0.04 | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters. | ||
| CVE-2016-8641 | Med | 0.40 | 6.7 | 0.01 | Aug 1, 2018 | A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and… |
- risk 0.42cvss 6.5epss 0.02
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
- risk 0.42cvss 6.1epss 0.35
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
- risk 0.41cvss 6.1epss 0.22
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
- risk 0.41cvss 6.3epss 0.01
Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a "kill…
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a…
- risk 0.40cvss 6.1epss 0.00
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject…
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch…
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
- risk 0.40cvss 6.1epss 0.02
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
- risk 0.40cvss 6.1epss 0.02
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
- risk 0.40cvss 6.1epss 0.04
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- risk 0.40cvss 6.1epss 0.12
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
- risk 0.40cvss 6.1epss 0.06
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.04
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
- risk 0.40cvss 6.7epss 0.01
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and…
Page 5 of 9