Nagios

Nagios Xi

195 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:45:53
  • Zuletzt bearbeitet 05.11.2025 18:22:07

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the...

  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:45:33
  • Zuletzt bearbeitet 05.11.2025 18:21:49

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a...

  • EPSS 0.71%
  • Veröffentlicht 30.10.2025 21:45:10
  • Zuletzt bearbeitet 05.11.2025 18:23:07

Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could su...

  • EPSS 1.49%
  • Veröffentlicht 30.10.2025 21:44:49
  • Zuletzt bearbeitet 05.11.2025 18:27:39

Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statements without adequate parameterization or sanitation, allowing an authe...

  • EPSS 0.29%
  • Veröffentlicht 30.10.2025 21:44:26
  • Zuletzt bearbeitet 06.11.2025 16:17:23

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after ...

  • EPSS 1%
  • Veröffentlicht 30.10.2025 21:43:55
  • Zuletzt bearbeitet 06.11.2025 16:18:50

Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can all...

  • EPSS 0.68%
  • Veröffentlicht 30.10.2025 21:43:34
  • Zuletzt bearbeitet 06.11.2025 15:16:09

Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute...

  • EPSS 0.9%
  • Veröffentlicht 30.10.2025 21:43:07
  • Zuletzt bearbeitet 06.11.2025 18:17:48

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated administrator to inject shell metacharacters that are in...

Medienbericht
  • EPSS 0.9%
  • Veröffentlicht 30.10.2025 21:42:44
  • Zuletzt bearbeitet 06.11.2025 18:13:04

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administr...

  • EPSS 1.27%
  • Veröffentlicht 30.10.2025 21:42:19
  • Zuletzt bearbeitet 06.11.2025 16:09:37

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach command execut...