Nagios

Nagios Xi

195 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:49:49
  • Zuletzt bearbeitet 05.11.2025 18:22:45

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a vic...

  • EPSS 0.23%
  • Veröffentlicht 30.10.2025 21:49:27
  • Zuletzt bearbeitet 05.11.2025 18:21:21

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context...

  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:49:05
  • Zuletzt bearbeitet 06.11.2025 14:32:23

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of the "backend_url" JavaScript link. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary ...

  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:48:44
  • Zuletzt bearbeitet 06.11.2025 14:55:20

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inje...

  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:48:05
  • Zuletzt bearbeitet 05.11.2025 18:22:32

Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the c...

  • EPSS 0.12%
  • Veröffentlicht 30.10.2025 21:47:42
  • Zuletzt bearbeitet 05.11.2025 18:21:40

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly validated or escaped, allowing injectio...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:47:19
  • Zuletzt bearbeitet 06.11.2025 16:22:37

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing ...

  • EPSS 0.89%
  • Veröffentlicht 30.10.2025 21:46:58
  • Zuletzt bearbeitet 05.11.2025 18:24:09

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file types or enforce storage outside of the webroot, and the web server perm...

  • EPSS 0.1%
  • Veröffentlicht 30.10.2025 21:46:37
  • Zuletzt bearbeitet 05.11.2025 18:24:56

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause...

  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:46:15
  • Zuletzt bearbeitet 05.11.2025 18:21:56

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the cont...