XI
by Nagios
CVEs (195)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24402 | Cri | 0.64 | 9.8 | 0.03 | Feb 26, 2024 | An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component. | ||
| CVE-2022-38250 | Cri | 0.64 | 9.8 | 0.03 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | ||
| CVE-2021-36366 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards. | ||
| CVE-2021-36365 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh. | ||
| CVE-2021-36364 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards. | ||
| CVE-2021-36363 | Cri | 0.64 | 9.8 | 0.04 | Sep 28, 2021 | Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php. | ||
| CVE-2020-28910 | Cri | 0.64 | 9.8 | 0.04 | May 24, 2021 | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh. | ||
| CVE-2020-28900 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2021 | Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh. | ||
| CVE-2021-3193 | Cri | 0.64 | 9.8 | 0.10 | Jan 26, 2021 | Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user. | ||
| CVE-2020-15903 | Cri | 0.64 | 9.8 | 0.05 | Sep 9, 2020 | An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3. | ||
| CVE-2018-17148 | Cri | 0.64 | 9.8 | 0.04 | Jun 19, 2019 | An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials. | ||
| CVE-2019-9165 | Cri | 0.64 | 9.8 | 0.05 | Mar 28, 2019 | SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id. | ||
| CVE-2018-8736 | Hig | 0.64 | 8.8 | 0.47 | Apr 18, 2018 | A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root. | ||
| CVE-2026-2043 | Hig | 0.63 | 8.8 | 0.73 | Feb 20, 2026 | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The… | ||
| CVE-2026-2041 | Hig | 0.63 | 8.8 | 0.73 | Feb 20, 2026 | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific… | ||
| CVE-2021-37343 | Hig | 0.62 | 8.8 | 0.24 | Aug 13, 2021 | A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios. | ||
| CVE-2019-9164 | Hig | 0.61 | 8.8 | 0.46 | Mar 28, 2019 | Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job. | ||
| CVE-2018-15711 | Hig | 0.60 | 8.8 | 0.36 | Nov 14, 2018 | Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges. | ||
| CVE-2025-34227 | Hig | 0.59 | 8.8 | 0.24 | Sep 25, 2025 | Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute… | ||
| CVE-2023-48082 | Cri | 0.59 | 9.1 | 0.02 | Oct 14, 2024 | Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate. |
- risk 0.64cvss 9.8epss 0.03
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
- risk 0.64cvss 9.8epss 0.03
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.
- risk 0.64cvss 9.8epss 0.04
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
- risk 0.64cvss 9.8epss 0.04
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.
- risk 0.64cvss 9.8epss 0.02
Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.
- risk 0.64cvss 9.8epss 0.10
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
- risk 0.64cvss 9.8epss 0.05
An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.
- risk 0.64cvss 9.8epss 0.04
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.
- risk 0.64cvss 9.8epss 0.05
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
- risk 0.64cvss 8.8epss 0.47
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.
- risk 0.63cvss 8.8epss 0.73
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The…
- risk 0.63cvss 8.8epss 0.73
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific…
- risk 0.62cvss 8.8epss 0.24
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
- risk 0.61cvss 8.8epss 0.46
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
- risk 0.60cvss 8.8epss 0.36
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
- risk 0.59cvss 8.8epss 0.24
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute…
- risk 0.59cvss 9.1epss 0.02
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
Page 2 of 10