VYPR

Vendor CVEs

Nagios

All CVEs

311 total · sorted by risk
  • CVE-2021-25298HigKEVFeb 15, 2021
    risk 0.78cvss 8.8epss 0.75

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can…

  • CVE-2021-25296HigKEVFeb 15, 2021
    risk 0.78cvss 8.8epss 0.72

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which…

  • CVE-2019-15949HigKEVSep 5, 2019
    risk 0.78cvss 8.8epss 0.78

    Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system profile (profile.php?cmd=download), is…

  • CVE-2021-25297HigKEVFeb 15, 2021
    risk 0.77cvss 8.8epss 0.56

    Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead…

  • CVE-2018-15708CriNov 14, 2018
    risk 0.74cvss 9.8epss 0.89

    Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

  • CVE-2021-37344CriAug 13, 2021
    risk 0.71cvss 9.8epss 0.97

    Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection).

  • CVE-2018-8734CriApr 18, 2018
    risk 0.71cvss 9.8epss 0.53

    SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

  • CVE-2023-48085CriDec 14, 2023
    risk 0.70cvss 9.8epss 0.76

    Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

  • CVE-2021-37350CriAug 13, 2021
    risk 0.70cvss 9.8epss 0.79

    Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

  • CVE-2021-37346CriAug 13, 2021
    risk 0.70cvss 9.8epss 0.74

    Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements used in an OS Command (OS Command injection).

  • CVE-2018-8733CriApr 18, 2018
    risk 0.69cvss 9.8epss 0.28

    Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

  • CVE-2016-9565CriDec 15, 2016
    risk 0.69cvss 9.8epss 0.23

    MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2024-24401CriFeb 26, 2024
    risk 0.67cvss 9.8epss 0.46

    SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

  • CVE-2019-12279CriMay 22, 2019
    risk 0.67cvss 9.8epss 0.04

    Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any…

  • CVE-2025-44823CriOct 7, 2025
    risk 0.66cvss 9.9epss 0.16

    Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.

  • CVE-2023-48084CriDec 14, 2023
    risk 0.66cvss 9.8epss 0.34

    Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

  • CVE-2019-9204CriMar 28, 2019
    risk 0.65cvss 9.8epss 0.20

    SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL commands.

  • CVE-2019-9203CriMar 28, 2019
    risk 0.65cvss 9.8epss 0.20

    Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.

  • CVE-2018-8735HigApr 18, 2018
    risk 0.65cvss 8.8epss 0.64

    Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

  • CVE-2023-53948CriDec 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a…

  • CVE-2025-34277CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to…

  • CVE-2025-34274CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin,…

  • CVE-2025-34271CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker…

  • CVE-2024-14003CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach command execution paths, enabling…

  • CVE-2024-13999CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of…

  • CVE-2024-13996CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This…

  • CVE-2024-13994CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized…

  • CVE-2012-10063CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to…

  • CVE-2025-25535CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.00

    HTTP Response Manipulation in SCRIPT CASE v.1.0.002 Build7 allows a remote attacker to escalate privileges via a crafted request.

  • CVE-2024-33775CriMay 1, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

  • CVE-2024-24402CriFeb 26, 2024
    risk 0.64cvss 9.8epss 0.03

    An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

  • CVE-2022-38250CriSep 7, 2022
    risk 0.64cvss 9.8epss 0.03

    Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

  • CVE-2021-36366CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.

  • CVE-2021-36365CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

  • CVE-2021-36364CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

  • CVE-2021-36363CriSep 28, 2021
    risk 0.64cvss 9.8epss 0.04

    Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

  • CVE-2021-37353CriAug 13, 2021
    risk 0.64cvss 9.8epss 0.03

    Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.

  • CVE-2020-28910CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.04

    Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

  • CVE-2020-28908CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.06

    Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.

  • CVE-2020-28907CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.03

    Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

  • CVE-2020-28904CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.04

    Execution with Unnecessary Privileges in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation as nagios via installation of a malicious component containing PHP code.

  • CVE-2020-28902CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.06

    Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.

  • CVE-2020-28901CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.09

    Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.

  • CVE-2020-28900CriMay 24, 2021
    risk 0.64cvss 9.8epss 0.02

    Insufficient Verification of Data Authenticity in Nagios Fusion 4.1.8 and earlier and Nagios XI 5.7.5 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to an untrusted update package to upgrade_to_latest.sh.

  • CVE-2021-28925CriApr 8, 2021
    risk 0.64cvss 9.8epss 0.04

    SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.

  • CVE-2021-3193CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.10

    Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.

  • CVE-2020-15903CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.05

    An issue was found in Nagios XI before 5.7.3. There is a privilege escalation vulnerability in backend scripts that ran as root where some included files were editable by nagios user. This issue was fixed in version 5.7.3.

  • CVE-2018-17148CriJun 19, 2019
    risk 0.64cvss 9.8epss 0.04

    An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

  • CVE-2019-9165CriMar 28, 2019
    risk 0.64cvss 9.8epss 0.05

    SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

  • CVE-2018-8736HigApr 18, 2018
    risk 0.64cvss 8.8epss 0.47

    A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

Page 1 of 7