Skip to main content

Vendor archive

nagios CVEs

Beta · best-effort

301 CVEs tagged to vendor nagios53 Critical, 99 High, 145 Medium, 4 Low, 0 Unrated.

CVE-2020-36865

Published Oct 30, 2025

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. Insu…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36864

Published Oct 30, 2025

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplie…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36863

Published Oct 30, 2025

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36862

Published Oct 30, 2025

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/re…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36861

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site scripting (XSS) vulnerabilities in the overlay UI elements an…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36860

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site scripting (XSS) vulnerabilities in the object edit pages. Ins…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36859

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36858

Published Oct 30, 2025

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insu…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36857

Published Oct 30, 2025

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36856

Published Oct 30, 2025

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` par…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-25123

Published Oct 30, 2025

Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25122

Published Oct 30, 2025

Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25121

Published Oct 30, 2025

Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-25119

Published Oct 30, 2025

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20209

Published Oct 30, 2025

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input may…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15053

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-suppl…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15052

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or escaping of user-supplied input…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15051

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient validat…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15050

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statem…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2016-15049

Published Oct 30, 2025

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log conten…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-10074

Published Oct 30, 2025

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-supplied inp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-10073

Published Oct 30, 2025

Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanita…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2013-10072

Published Oct 30, 2025

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints an…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-10071

Published Oct 30, 2025

Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or esca…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-10063

Published Oct 30, 2025

Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queri…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 301 CVEsPage 4 of 13