Nagios

Nagios Xi

203 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 14.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 19:56:19

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.

  • EPSS 0.77%
  • Veröffentlicht 14.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 19:56:19

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison...

  • EPSS 0.17%
  • Veröffentlicht 26.08.2026 15:37:20
  • Zuletzt bearbeitet 24.09.2026 20:44:42

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId values in the POST b...

  • EPSS 0.52%
  • Veröffentlicht 12.08.2026 16:48:27
  • Zuletzt bearbeitet 08.09.2026 20:28:37

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCO...

  • EPSS 0.52%
  • Veröffentlicht 12.08.2026 16:46:35
  • Zuletzt bearbeitet 08.09.2026 20:28:37

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or c...

  • EPSS 0.17%
  • Veröffentlicht 12.08.2026 16:34:33
  • Zuletzt bearbeitet 08.09.2026 20:28:37

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to ...

  • EPSS 0.17%
  • Veröffentlicht 12.08.2026 16:32:16
  • Zuletzt bearbeitet 08.09.2026 20:28:37

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, en...

  • EPSS 0.27%
  • Veröffentlicht 12.08.2026 16:30:02
  • Zuletzt bearbeitet 08.09.2026 20:28:37

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated use...

  • EPSS 73.37%
  • Veröffentlicht 20.02.2026 22:22:18
  • Zuletzt bearbeitet 24.02.2026 13:18:09

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this...

  • EPSS 72.91%
  • Veröffentlicht 20.02.2026 22:22:06
  • Zuletzt bearbeitet 24.02.2026 13:16:42

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to explo...