CVE-2024-54961
- EPSS 6.27%
- Veröffentlicht 20.02.2025 18:15:25
- Zuletzt bearbeitet 18.06.2025 23:39:55
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
CVE-2024-42898
- EPSS 5.34%
- Veröffentlicht 09.01.2025 20:15:38
- Zuletzt bearbeitet 24.06.2025 14:27:00
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
CVE-2023-48082
- EPSS 1.15%
- Veröffentlicht 14.10.2024 19:15:10
- Zuletzt bearbeitet 10.07.2025 17:06:27
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
CVE-2024-33775
- EPSS 3.38%
- Veröffentlicht 01.05.2024 13:15:52
- Zuletzt bearbeitet 30.06.2025 15:22:14
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVE-2024-24401
- EPSS 54.82%
- Veröffentlicht 26.02.2024 17:15:10
- Zuletzt bearbeitet 27.06.2025 13:23:42
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
CVE-2024-24402
- EPSS 24.89%
- Veröffentlicht 26.02.2024 17:15:10
- Zuletzt bearbeitet 24.03.2025 20:15:17
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
CVE-2023-51072
- EPSS 1.77%
- Veröffentlicht 02.02.2024 10:15:08
- Zuletzt bearbeitet 16.06.2025 19:15:25
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation...
CVE-2023-48085
- EPSS 62.4%
- Veröffentlicht 14.12.2023 07:15:09
- Zuletzt bearbeitet 22.05.2025 18:15:29
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.
CVE-2023-48084
- EPSS 82.09%
- Veröffentlicht 14.12.2023 07:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:04
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
CVE-2023-40932
- EPSS 1.96%
- Veröffentlicht 19.09.2023 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:20:19
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing ...