Vulnerabilities (CVE)

Filtered by vendor Nagios Subscribe
Filtered by product Nagios Xi
Total 104 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29271 1 Nagios 1 Nagios Xi 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
CVE-2022-29269 1 Nagios 1 Nagios Xi 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
CVE-2022-29270 1 Nagios 1 Nagios Xi 2023-08-08 4.0 MEDIUM 4.3 MEDIUM
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
CVE-2020-5791 1 Nagios 1 Nagios Xi 2023-01-24 9.0 HIGH 7.2 HIGH
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute operating system commands with the privileges of the apache user.
CVE-2020-15901 1 Nagios 1 Nagios Xi 2022-12-03 7.5 HIGH 8.8 HIGH
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
CVE-2020-15902 1 Nagios 1 Nagios Xi 2022-11-16 4.3 MEDIUM 6.1 MEDIUM
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
CVE-2021-40345 1 Nagios 1 Nagios Xi 2022-11-08 9.0 HIGH 7.2 HIGH
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
CVE-2020-28648 1 Nagios 1 Nagios Xi 2022-10-18 9.0 HIGH 8.8 HIGH
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
CVE-2019-9167 1 Nagios 1 Nagios Xi 2022-10-06 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Nagios XI before 5.5.11 allows attackers to inject arbitrary web script or HTML via the xiwindow parameter.
CVE-2019-9166 1 Nagios 1 Nagios Xi 2022-10-06 7.2 HIGH 7.8 HIGH
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.
CVE-2019-9165 1 Nagios 1 Nagios Xi 2022-10-06 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.
CVE-2019-9164 1 Nagios 1 Nagios Xi 2022-10-06 6.5 MEDIUM 8.8 HIGH
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
CVE-2022-38247 1 Nagios 1 Nagios Xi 2022-09-09 N/A 4.8 MEDIUM
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.
CVE-2022-38248 1 Nagios 1 Nagios Xi 2022-09-09 N/A 6.1 MEDIUM
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
CVE-2022-38249 1 Nagios 1 Nagios Xi 2022-09-09 N/A 6.1 MEDIUM
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
CVE-2022-38250 1 Nagios 1 Nagios Xi 2022-09-09 N/A 9.8 CRITICAL
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
CVE-2022-38251 1 Nagios 1 Nagios Xi 2022-09-09 N/A 4.8 MEDIUM
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
CVE-2022-38254 1 Nagios 1 Nagios Xi 2022-09-09 N/A 6.1 MEDIUM
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
CVE-2020-28910 1 Nagios 1 Nagios Xi 2022-07-12 10.0 HIGH 9.8 CRITICAL
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.
CVE-2021-37349 1 Nagios 1 Nagios Xi 2022-07-12 4.6 MEDIUM 7.8 HIGH
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.