CVE-2023-24034
- EPSS 0.39%
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 19:56:19
An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
CVE-2023-24035
- EPSS 0.77%
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 19:56:19
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison...
CVE-2026-48549
- EPSS 0.17%
- Veröffentlicht 26.08.2026 15:37:20
- Zuletzt bearbeitet 24.09.2026 20:44:42
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST b...
CVE-2026-48554
- EPSS 0.52%
- Veröffentlicht 12.08.2026 16:48:27
- Zuletzt bearbeitet 08.09.2026 20:28:37
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCO...
CVE-2026-48553
- EPSS 0.52%
- Veröffentlicht 12.08.2026 16:46:35
- Zuletzt bearbeitet 08.09.2026 20:28:37
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or c...
CVE-2026-48552
- EPSS 0.17%
- Veröffentlicht 12.08.2026 16:34:33
- Zuletzt bearbeitet 08.09.2026 20:28:37
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to ...
CVE-2026-48551
- EPSS 0.17%
- Veröffentlicht 12.08.2026 16:32:16
- Zuletzt bearbeitet 08.09.2026 20:28:37
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, en...
CVE-2026-48550
- EPSS 0.27%
- Veröffentlicht 12.08.2026 16:30:02
- Zuletzt bearbeitet 08.09.2026 20:28:37
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated use...
CVE-2026-2041
- EPSS 73.37%
- Veröffentlicht 20.02.2026 22:22:18
- Zuletzt bearbeitet 24.02.2026 13:18:09
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this...
CVE-2026-2043
- EPSS 72.91%
- Veröffentlicht 20.02.2026 22:22:06
- Zuletzt bearbeitet 24.02.2026 13:16:42
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to explo...