Nagios

Nagios Xi

189 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 03.11.2025 21:56:26
  • Zuletzt bearbeitet 10.11.2025 18:15:34

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a downstream effect of an already identified vulnerability, CVE-2012-6708.

  • EPSS 0.43%
  • Veröffentlicht 03.11.2025 21:56:10
  • Zuletzt bearbeitet 07.11.2025 12:55:54

Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inje...

  • EPSS 0.15%
  • Veröffentlicht 03.11.2025 21:55:48
  • Zuletzt bearbeitet 06.11.2025 16:24:49

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workfl...

  • EPSS 0.95%
  • Veröffentlicht 03.11.2025 21:53:51
  • Zuletzt bearbeitet 06.11.2025 16:25:49

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or passwor...

  • EPSS 0.64%
  • Veröffentlicht 31.10.2025 12:35:56
  • Zuletzt bearbeitet 06.11.2025 18:12:02

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate ...

  • EPSS 0.62%
  • Veröffentlicht 30.10.2025 21:57:27
  • Zuletzt bearbeitet 06.11.2025 17:15:41

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker t...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:57:03
  • Zuletzt bearbeitet 05.11.2025 18:22:39

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context ...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:56:43
  • Zuletzt bearbeitet 05.11.2025 18:26:57

Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the co...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:56:22
  • Zuletzt bearbeitet 06.11.2025 16:23:26

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the ...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:55:55
  • Zuletzt bearbeitet 06.11.2025 15:08:55

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute ...