CVE-2021-37223
- EPSS 4.94%
- Veröffentlicht 05.10.2021 12:15:07
- Zuletzt bearbeitet 09.07.2026 01:16:58
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI application. Due to lac...
CVE-2021-36363
- EPSS 3.8%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
CVE-2021-36364
- EPSS 4%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.
CVE-2021-36365
- EPSS 3.8%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
CVE-2021-36366
- EPSS 4%
- Veröffentlicht 28.09.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:13:36
Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.
CVE-2021-38156
- EPSS 88.94%
- Veröffentlicht 15.09.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:30
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
CVE-2021-37345
- EPSS 0.57%
- Veröffentlicht 13.08.2021 12:15:07
- Zuletzt bearbeitet 09.07.2026 01:16:59
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
CVE-2021-37347
- EPSS 0.78%
- Veröffentlicht 13.08.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:59
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
CVE-2021-37348
- EPSS 2.78%
- Veröffentlicht 13.08.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:59
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
CVE-2021-37349
- EPSS 0.67%
- Veröffentlicht 13.08.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:59
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.