Nagios

Nagios Xi

203 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.33%
  • Veröffentlicht 20.02.2025 18:15:25
  • Zuletzt bearbeitet 07.07.2025 17:46:10

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.

  • EPSS 1.59%
  • Veröffentlicht 20.02.2025 18:15:25
  • Zuletzt bearbeitet 18.06.2025 23:39:55

Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 09.01.2025 20:15:38
  • Zuletzt bearbeitet 24.06.2025 14:27:00

A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.

  • EPSS 1.54%
  • Veröffentlicht 14.10.2024 19:15:10
  • Zuletzt bearbeitet 10.07.2025 17:06:27

Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.

Exploit
  • EPSS 1.6%
  • Veröffentlicht 01.05.2024 13:15:52
  • Zuletzt bearbeitet 24.08.2026 14:16:48

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

  • EPSS 45.88%
  • Veröffentlicht 26.02.2024 17:15:10
  • Zuletzt bearbeitet 27.06.2025 13:23:42

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

  • EPSS 3.4%
  • Veröffentlicht 26.02.2024 17:15:10
  • Zuletzt bearbeitet 24.03.2025 20:15:17

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

  • EPSS 1.26%
  • Veröffentlicht 02.02.2024 10:15:08
  • Zuletzt bearbeitet 16.06.2025 19:15:25

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation...

  • EPSS 75.84%
  • Veröffentlicht 14.12.2023 07:15:09
  • Zuletzt bearbeitet 22.05.2025 18:15:29

Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.

  • EPSS 33.74%
  • Veröffentlicht 14.12.2023 07:15:08
  • Zuletzt bearbeitet 21.11.2024 08:31:04

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.