Vendor CVEs
Nagios
All CVEs
311 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-6584 | Med | 0.43 | 6.5 | 0.04 | Mar 16, 2020 | Nagios Log Server 2.1.3 has Incorrect Access Control. | ||
| CVE-2024-13998 | Med | 0.42 | 6.5 | 0.01 | Nov 3, 2025 | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to… | ||
| CVE-2025-34283 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value. | ||
| CVE-2025-34273 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard deletion workflow, enabling… | ||
| CVE-2025-34272 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2025 | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's… | ||
| CVE-2013-10072 | Med | 0.42 | 6.5 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing… | ||
| CVE-2024-54961 | Med | 0.42 | 6.5 | 0.02 | Feb 20, 2025 | Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users. | ||
| CVE-2024-54960 | Med | 0.42 | 6.5 | 0.01 | Feb 20, 2025 | A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component. | ||
| CVE-2022-29271 | Med | 0.42 | 6.5 | 0.02 | Jun 29, 2022 | In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks. | ||
| CVE-2022-29269 | Med | 0.42 | 6.5 | 0.03 | Jun 29, 2022 | In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address. | ||
| CVE-2021-38156 | Med | 0.42 | 5.4 | 0.89 | Sep 15, 2021 | In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard. | ||
| CVE-2020-28911 | Med | 0.42 | 6.5 | 0.03 | May 24, 2021 | Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php. | ||
| CVE-2021-26023 | Med | 0.42 | 6.1 | 0.25 | Feb 3, 2021 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. | ||
| CVE-2020-27988 | Med | 0.42 | 5.4 | 0.87 | Nov 16, 2020 | Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field). | ||
| CVE-2020-5790 | Med | 0.42 | 6.5 | 0.02 | Oct 20, 2020 | Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | ||
| CVE-2020-15902 | Med | 0.42 | 6.1 | 0.35 | Jul 22, 2020 | Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option. | ||
| CVE-2021-35478 | Med | 0.41 | 5.4 | 0.77 | Jul 30, 2021 | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page. | ||
| CVE-2020-25385 | Med | 0.41 | 6.1 | 0.16 | Jan 20, 2021 | Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page. | ||
| CVE-2019-9167 | Med | 0.41 | 6.1 | 0.22 | Mar 28, 2019 | Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter. | ||
| CVE-2017-12847 | Med | 0.41 | 6.3 | 0.01 | Aug 23, 2017 | Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a "kill… | ||
| CVE-2026-48550 | Med | 0.40 | 6.1 | 0.00 | Aug 12, 2026 | Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary… | ||
| CVE-2024-14006 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to… | ||
| CVE-2024-13993 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a… | ||
| CVE-2021-47694 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject… | ||
| CVE-2020-36862 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch… | ||
| CVE-2018-25119 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | ||
| CVE-2017-20209 | Med | 0.40 | 6.1 | 0.00 | Oct 30, 2025 | Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | ||
| CVE-2013-10071 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2025 | Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the… | ||
| CVE-2025-56432 | Med | 0.40 | 6.1 | 0.01 | Aug 26, 2025 | A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for… | ||
| CVE-2024-54957 | Med | 0.40 | 6.1 | 0.01 | Feb 27, 2025 | Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent. | ||
| CVE-2024-54959 | Med | 0.40 | 6.1 | 0.01 | Feb 20, 2025 | Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS). | ||
| CVE-2024-54958 | Med | 0.40 | 6.1 | 0.01 | Feb 20, 2025 | Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page. | ||
| CVE-2020-23992 | Med | 0.40 | 6.1 | 0.02 | Aug 22, 2023 | Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request. | ||
| CVE-2022-38254 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5. | ||
| CVE-2022-38249 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4. | ||
| CVE-2022-38248 | Med | 0.40 | 6.1 | 0.02 | Sep 7, 2022 | Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. | ||
| CVE-2022-29272 | Med | 0.40 | 6.1 | 0.04 | Jun 29, 2022 | In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing. | ||
| CVE-2021-33179 | Med | 0.40 | 6.1 | 0.12 | Oct 14, 2021 | The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload. | ||
| CVE-2021-37352 | Med | 0.40 | 6.1 | 0.06 | Aug 13, 2021 | An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link. | ||
| CVE-2020-28903 | Med | 0.40 | 6.1 | 0.10 | May 24, 2021 | Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS. | ||
| CVE-2021-28924 | Med | 0.40 | 6.1 | 0.09 | Apr 8, 2021 | Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page. | ||
| CVE-2019-15898 | Med | 0.40 | 6.1 | 0.02 | Sep 3, 2019 | Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page. | ||
| CVE-2018-20172 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-20171 | Med | 0.40 | 6.1 | 0.02 | Dec 17, 2018 | An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability. | ||
| CVE-2018-15714 | Med | 0.40 | 6.1 | 0.04 | Nov 14, 2018 | Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters. | ||
| CVE-2016-8641 | Med | 0.40 | 6.7 | 0.01 | Aug 1, 2018 | A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and… | ||
| CVE-2018-12501 | Med | 0.40 | 6.1 | 0.02 | Jun 16, 2018 | Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335. | ||
| CVE-2015-3618 | Med | 0.40 | 6.1 | 0.01 | Feb 6, 2018 | Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php. | ||
| CVE-2016-6209 | Med | 0.40 | 6.1 | 0.02 | Mar 31, 2017 | Cross-site scripting (XSS) vulnerability in Nagios. | ||
| CVE-2018-13458 | Med | 0.39 | 5.5 | 0.05 | Jul 12, 2018 | qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket. |
- risk 0.43cvss 6.5epss 0.04
Nagios Log Server 2.1.3 has Incorrect Access Control.
- risk 0.42cvss 6.5epss 0.01
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to…
- risk 0.42cvss 6.5epss 0.01
Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
- risk 0.42cvss 6.5epss 0.01
Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard deletion workflow, enabling…
- risk 0.42cvss 6.5epss 0.01
In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's…
- risk 0.42cvss 6.5epss 0.01
Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing…
- risk 0.42cvss 6.5epss 0.02
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
- risk 0.42cvss 6.5epss 0.01
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
- risk 0.42cvss 6.5epss 0.02
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
- risk 0.42cvss 6.5epss 0.03
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
- risk 0.42cvss 5.4epss 0.89
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
- risk 0.42cvss 6.5epss 0.03
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
- risk 0.42cvss 6.1epss 0.25
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
- risk 0.42cvss 5.4epss 0.87
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
- risk 0.42cvss 6.5epss 0.02
Cross-site request forgery in Nagios XI 5.7.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
- risk 0.42cvss 6.1epss 0.35
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
- risk 0.41cvss 5.4epss 0.77
Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or third-party web page.
- risk 0.41cvss 6.1epss 0.16
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
- risk 0.41cvss 6.1epss 0.22
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
- risk 0.41cvss 6.3epss 0.01
Nagios Core before 4.3.3 creates a nagios.lock PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for nagios.lock modification before a root script executes a "kill…
- risk 0.40cvss 6.1epss 0.00
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary…
- risk 0.40cvss 6.1epss 0.00
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to…
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a…
- risk 0.40cvss 6.1epss 0.00
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject…
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch…
- risk 0.40cvss 6.1epss 0.00
Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
- risk 0.40cvss 6.1epss 0.00
Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
- risk 0.40cvss 6.1epss 0.01
Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the…
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for…
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
- risk 0.40cvss 6.1epss 0.01
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
- risk 0.40cvss 6.1epss 0.02
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
- risk 0.40cvss 6.1epss 0.02
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
- risk 0.40cvss 6.1epss 0.02
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
- risk 0.40cvss 6.1epss 0.04
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
- risk 0.40cvss 6.1epss 0.12
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting. An authenticated victim, who accesses a specially crafted malicious URL, would unknowingly execute the attached payload.
- risk 0.40cvss 6.1epss 0.06
An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.
- risk 0.40cvss 6.1epss 0.10
Improper input validation in Nagios Fusion 4.1.8 and earlier allows a remote attacker with control over a fused server to inject arbitrary HTML, aka XSS.
- risk 0.40cvss 6.1epss 0.09
Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
- risk 0.40cvss 6.1epss 0.02
Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The rss_url parameter of rss_dashlet/magpierss/scripts/magpie_slashbox.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in Nagios XI before 5.5.8. The url parameter of rss_dashlet/magpierss/scripts/magpie_simple.php is not filtered, resulting in an XSS vulnerability.
- risk 0.40cvss 6.1epss 0.04
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
- risk 0.40cvss 6.7epss 0.01
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and…
- risk 0.40cvss 6.1epss 0.02
Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
- risk 0.40cvss 6.1epss 0.02
Cross-site scripting (XSS) vulnerability in Nagios.
- risk 0.39cvss 5.5epss 0.05
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.
Page 4 of 7