CVE-2024-13992
- EPSS 0.99%
- Veröffentlicht 31.10.2025 12:35:56
- Zuletzt bearbeitet 06.11.2025 18:12:02
Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate ...
CVE-2011-10037
- EPSS 0.96%
- Veröffentlicht 30.10.2025 21:57:27
- Zuletzt bearbeitet 06.11.2025 17:15:41
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker t...
CVE-2021-47697
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:57:03
- Zuletzt bearbeitet 05.11.2025 18:22:39
Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context ...
CVE-2018-25121
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:56:43
- Zuletzt bearbeitet 05.11.2025 18:26:57
Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the co...
CVE-2013-10074
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:56:22
- Zuletzt bearbeitet 06.11.2025 16:23:26
Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the ...
CVE-2011-10040
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:55:55
- Zuletzt bearbeitet 06.11.2025 15:08:55
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute ...
CVE-2016-15051
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:55:32
- Zuletzt bearbeitet 05.11.2025 18:27:28
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient validation or escaping of user-supplied input may allow an attacker to inject ...
CVE-2011-10038
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:55:10
- Zuletzt bearbeitet 06.11.2025 14:41:20
Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary...
CVE-2021-47695
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:54:48
- Zuletzt bearbeitet 05.11.2025 18:22:54
Nagios XI versions prior to 5.8.0 are vulnerable to stored cross-site scripting (XSS) via the My Tools page. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a v...
CVE-2016-15053
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:54:25
- Zuletzt bearbeitet 05.11.2025 18:27:07
Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script ...