VYPR

XI

by Nagios

CVEs (195)

  • CVE-2025-34288MedDec 16, 2025
    risk 0.44cvss 6.7epss 0.02

    Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be executed as root via sudo and includes an application file…

  • CVE-2018-15712MedNov 14, 2018
    risk 0.44cvss 6.1epss 0.49

    Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.

  • CVE-2023-40931MedSep 19, 2023
    risk 0.43cvss 6.5epss 0.11

    A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php

  • CVE-2021-37223MedOct 5, 2021
    risk 0.43cvss 6.5epss 0.05

    Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lack of input sanitisation, the…

  • CVE-2024-13998MedNov 3, 2025
    risk 0.42cvss 6.5epss 0.01

    Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to…

  • CVE-2025-34283MedOct 30, 2025
    risk 0.42cvss 6.5epss 0.01

    Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.

  • CVE-2013-10072MedOct 30, 2025
    risk 0.42cvss 6.5epss 0.01

    Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing…

  • CVE-2024-54961MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.02

    Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.

  • CVE-2024-54960MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.01

    A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

  • CVE-2022-29271MedJun 29, 2022
    risk 0.42cvss 6.5epss 0.02

    In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.

  • CVE-2022-29269MedJun 29, 2022
    risk 0.42cvss 6.5epss 0.03

    In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.

  • CVE-2021-38156MedSep 15, 2021
    risk 0.42cvss 5.4epss 0.89

    In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.

  • CVE-2021-26023MedFeb 3, 2021
    risk 0.42cvss 6.1epss 0.25

    The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.

  • CVE-2020-27988MedNov 16, 2020
    risk 0.42cvss 5.4epss 0.91

    Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).

  • CVE-2020-5790MedOct 20, 2020
    risk 0.42cvss 6.5epss 0.02

    Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

  • CVE-2020-15902MedJul 22, 2020
    risk 0.42cvss 6.1epss 0.35

    Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.

  • CVE-2019-9167MedMar 28, 2019
    risk 0.41cvss 6.1epss 0.22

    Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.

  • CVE-2024-14006MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to…

  • CVE-2024-13993MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.01

    Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a…

  • CVE-2021-47694MedOct 30, 2025
    risk 0.40cvss 6.1epss 0.00

    The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject…

Page 6 of 10