Nagios
by Nagios
Source repositories
CVEs (181)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38249 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4. | ||
| CVE-2022-38248 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. | ||
| CVE-2022-29272 | Med | 0.40 | 6.1 | 0.04 | Jun 29, 2022 | In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing. | ||
| CVE-2021-33179 | Med | 0.40 | 6.1 | 0.12 | Oct 14, 2021 | The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload. | ||
| CVE-2021-37352 | Med | 0.40 | 6.1 | 0.06 | Aug 13, 2021 | An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link. | ||
| CVE-2018-20172 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-20171 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-15714 | Med | 0.40 | 6.1 | 0.04 | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters. | ||
| CVE-2016-8641 | Med | 0.40 | 6.7 | 0.01 | Aug 1, 2018 | A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and… | ||
| CVE-2016-6209 | Med | 0.40 | 6.1 | 0.02 | Mar 31, 2017 | Cross-site scripting (XSS) vulnerability in Nagios. | ||
| CVE-2018-13441 | Med | 0.39 | 5.5 | 0.01 | Jul 12, 2018 | qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket. | ||
| CVE-2020-27991 | Med | 0.37 | 5.4 | 0.34 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field). | ||
| CVE-2020-27990 | Med | 0.37 | 5.4 | 0.34 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent). | ||
| CVE-2020-27989 | Med | 0.37 | 5.4 | 0.34 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard). | ||
| CVE-2020-10821 | Med | 0.37 | 4.8 | 0.71 | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter. | ||
| CVE-2020-10819 | Med | 0.37 | 4.8 | 0.71 | Mar 22, 2020 | Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter. | ||
| CVE-2020-6586 | Med | 0.37 | 5.4 | 0.19 | Mar 16, 2020 | Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered. | ||
| CVE-2019-3698 | Med | 0.37 | 5.7 | 0.01 | Feb 28, 2020 | UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This… | ||
| CVE-2024-14002 | Med | 0.36 | 5.5 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the… | ||
| CVE-2018-15713 | Med | 0.36 | 5.4 | 0.07 | Nov 14, 2018 | Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php. |
- risk 0.40cvss 6.1epss 0.02
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
- risk 0.40cvss 6.1epss 0.04
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- risk 0.40cvss 6.1epss 0.12
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
- risk 0.40cvss 6.1epss 0.06
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.04
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
- risk 0.40cvss 6.7epss 0.01
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and…
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in Nagios.
- risk 0.39cvss 5.5epss 0.01
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
- risk 0.37cvss 5.4epss 0.34
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
- risk 0.37cvss 5.4epss 0.34
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
- risk 0.37cvss 5.4epss 0.34
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
- risk 0.37cvss 4.8epss 0.71
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
- risk 0.37cvss 4.8epss 0.71
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
- risk 0.37cvss 5.4epss 0.19
Nagios Log Server 2.1.3 allows XSS by visiting /profile and entering a crafted name field that is mishandled on the /admin/users page. Any malicious user with limited access can store an XSS payload in his Name. When any admin views this, the XSS is triggered.
- risk 0.37cvss 5.7epss 0.01
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially escalate privileges by winning a race. This…
- risk 0.36cvss 5.5epss 0.01
Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the…
- risk 0.36cvss 5.4epss 0.07
Nagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
Page 6 of 10