VYPR

XI

by Nagios

CVEs (195)

  • CVE-2024-24402CriFeb 26, 2024
    risk 0.64cvss 9.8epss 0.03

    An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

  • CVE-2022-38250CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.03

    Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

  • CVE-2021-36366CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

  • CVE-2021-36365CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

  • CVE-2021-36364CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

  • CVE-2021-36363CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

  • CVE-2020-28910CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.04

    Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

  • CVE-2020-28900CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.02

    Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

  • CVE-2021-3193CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.10

    Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.

  • CVE-2020-15903CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.05

    An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.

  • CVE-2018-17148CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.04

    An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

  • CVE-2019-9165CriMar 28, 2019
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

  • CVE-2018-8736HigApr 18, 2018
    risk 0.64cvss 8.8epss 0.47

    A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

  • CVE-2026-2043HigFeb 20, 2026
    risk 0.63cvss 8.8epss 0.73

    Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The…

  • CVE-2026-2041HigFeb 20, 2026
    risk 0.63cvss 8.8epss 0.73

    Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2021-37343HigAug 13, 2021
    risk 0.62cvss 8.8epss 0.24

    A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.

  • CVE-2019-9164HigMar 28, 2019
    risk 0.61cvss 8.8epss 0.46

    Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.

  • CVE-2018-15711HigNov 14, 2018
    risk 0.60cvss 8.8epss 0.36

    Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.

  • CVE-2025-34227HigSep 25, 2025
    risk 0.59cvss 8.8epss 0.24

    Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute…

  • CVE-2023-48082CriOct 14, 2024
    risk 0.59cvss 9.1epss 0.02

    Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.

Page 2 of 10