Skip to main content

Vendor archive

nagios CVEs

Beta · best-effort

301 CVEs tagged to vendor nagios53 Critical, 99 High, 145 Medium, 4 Low, 0 Unrated.

CVE-2011-10040

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escap…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-10039

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the web interface. Insufficient vali…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-10038

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping of us…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-10037

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficien…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-10036

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of use…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-10035

Published Oct 30, 2025

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use ra…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60425

Published Oct 27, 2025

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a se…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60424

Published Oct 27, 2025

A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44824

Published Oct 7, 2025

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsy…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-44823

Published Oct 7, 2025

Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-34227

Published Sep 25, 2025

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wi…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-13986

Published Aug 28, 2025

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface.…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56432

Published Aug 26, 2025

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-28059

Published Apr 18, 2025

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale toke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-29471

Published Apr 15, 2025

Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-28132

Published Apr 1, 2025

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account t…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-28131

Published Apr 1, 2025

A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stoppin…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54957

Published Feb 27, 2025

Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a ma…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54961

Published Feb 20, 2025

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54960

Published Feb 20, 2025

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54959

Published Feb 20, 2025

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54958

Published Feb 20, 2025

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42898

Published Jan 9, 2025

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48082

Published Oct 14, 2024

Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all user…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-43199

Published Aug 7, 2024

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 101-125 of 301 CVEsPage 5 of 13