CVE-2026-48554
- EPSS 0.52%
- Veröffentlicht 12.08.2026 16:48:27
- Zuletzt bearbeitet 12.08.2026 18:17:30
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCO...
CVE-2026-48553
- EPSS 0.52%
- Veröffentlicht 12.08.2026 16:46:35
- Zuletzt bearbeitet 12.08.2026 20:17:44
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or c...
CVE-2026-48552
- EPSS 0.17%
- Veröffentlicht 12.08.2026 16:34:33
- Zuletzt bearbeitet 12.08.2026 17:17:27
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to ...
CVE-2026-48551
- EPSS 0.17%
- Veröffentlicht 12.08.2026 16:32:16
- Zuletzt bearbeitet 13.08.2026 17:17:22
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, en...
CVE-2026-48550
- EPSS 0.27%
- Veröffentlicht 12.08.2026 16:30:02
- Zuletzt bearbeitet 12.08.2026 19:17:34
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated use...
CVE-2026-2041
- EPSS 73.37%
- Veröffentlicht 20.02.2026 22:22:18
- Zuletzt bearbeitet 24.02.2026 13:18:09
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this...
CVE-2026-2043
- EPSS 72.91%
- Veröffentlicht 20.02.2026 22:22:06
- Zuletzt bearbeitet 24.02.2026 13:16:42
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to explo...
CVE-2026-2042
- EPSS 5.52%
- Veröffentlicht 20.02.2026 22:21:44
- Zuletzt bearbeitet 24.02.2026 13:17:25
Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerabilit...
CVE-2025-67254
- EPSS 1.82%
- Veröffentlicht 29.12.2025 00:00:00
- Zuletzt bearbeitet 15.01.2026 02:13:36
NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
CVE-2025-67255
- EPSS 0.99%
- Veröffentlicht 29.12.2025 00:00:00
- Zuletzt bearbeitet 15.01.2026 02:14:23
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.