CVE-2024-54958
- EPSS 3.8%
- Veröffentlicht 20.02.2025 18:15:25
- Zuletzt bearbeitet 01.07.2025 15:02:14
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other ...
CVE-2024-54959
- EPSS 3.8%
- Veröffentlicht 20.02.2025 18:15:25
- Zuletzt bearbeitet 01.07.2025 15:02:21
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
CVE-2024-54960
- EPSS 3.15%
- Veröffentlicht 20.02.2025 18:15:25
- Zuletzt bearbeitet 07.07.2025 17:46:10
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
CVE-2024-54961
- EPSS 6.27%
- Veröffentlicht 20.02.2025 18:15:25
- Zuletzt bearbeitet 18.06.2025 23:39:55
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
CVE-2024-42898
- EPSS 2.8%
- Veröffentlicht 09.01.2025 20:15:38
- Zuletzt bearbeitet 24.06.2025 14:27:00
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
CVE-2023-48082
- EPSS 1.55%
- Veröffentlicht 14.10.2024 19:15:10
- Zuletzt bearbeitet 10.07.2025 17:06:27
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
CVE-2024-33775
- EPSS 3.38%
- Veröffentlicht 01.05.2024 13:15:52
- Zuletzt bearbeitet 30.06.2025 15:22:14
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVE-2024-24401
- EPSS 57.97%
- Veröffentlicht 26.02.2024 17:15:10
- Zuletzt bearbeitet 27.06.2025 13:23:42
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
CVE-2024-24402
- EPSS 27.7%
- Veröffentlicht 26.02.2024 17:15:10
- Zuletzt bearbeitet 24.03.2025 20:15:17
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
CVE-2023-51072
- EPSS 1.77%
- Veröffentlicht 02.02.2024 10:15:08
- Zuletzt bearbeitet 16.06.2025 19:15:25
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation...