VYPR

XI

by Nagios

CVEs (195)

  • CVE-2020-15901HigJul 22, 2020
    risk 0.59cvss 8.8epss 0.22

    In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.

  • CVE-2019-20197HigDec 31, 2019
    risk 0.59cvss 8.8epss 0.22

    In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.

  • CVE-2018-15709HigNov 14, 2018
    risk 0.59cvss 8.8epss 0.21

    Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2026-2042HigFeb 20, 2026
    risk 0.58cvss 8.8epss 0.06

    Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2025-34284HigOct 30, 2025
    risk 0.58cvss 8.8epss 0.04

    Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations.…

  • CVE-2024-14005HigOct 30, 2025
    risk 0.58cvss 8.8epss 0.04

    Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command…

  • CVE-2021-33177HigOct 14, 2021
    risk 0.58cvss 8.8epss 0.10

    The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.

  • CVE-2020-28906HigMay 24, 2021
    risk 0.58cvss 8.8epss 0.05

    Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.

  • CVE-2020-24899HigFeb 15, 2021
    risk 0.58cvss 8.8epss 0.17

    Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query.

  • CVE-2020-28648HigNov 16, 2020
    risk 0.58cvss 8.8epss 0.06

    Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.

  • CVE-2025-67255HigDec 29, 2025
    risk 0.57cvss 8.8epss 0.01

    In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

  • CVE-2024-14004HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain…

  • CVE-2024-13995HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes…

  • CVE-2023-7317HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.02

    Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command…

  • CVE-2021-47693HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search text handling. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing…

  • CVE-2020-36867HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.03

    Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or…

  • CVE-2020-36863HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file types or enforce storage outside of the webroot, and the web server permitted execution within the…

  • CVE-2020-36859HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.01

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing…

  • CVE-2020-36856HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.02

    Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Manager to inject shell…

  • CVE-2018-25122HigOct 30, 2025
    risk 0.57cvss 8.8epss 0.02

    Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output encoding, allowing an…

Page 3 of 10