CVE-2025-34287
- EPSS 0.01%
- Veröffentlicht 30.10.2025 21:39:43
- Zuletzt bearbeitet 06.11.2025 18:12:41
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges cou...
CVE-2025-34135
- EPSS 0.03%
- Veröffentlicht 30.10.2025 21:39:22
- Zuletzt bearbeitet 06.11.2025 18:16:51
Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permissions that were not required. Overly permissive permissions on service...
CVE-2021-47700
- EPSS 0.08%
- Veröffentlicht 30.10.2025 21:39:02
- Zuletzt bearbeitet 05.11.2025 18:22:22
Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking di...
CVE-2024-14006
- EPSS 0.13%
- Veröffentlicht 30.10.2025 21:38:42
- Zuletzt bearbeitet 06.11.2025 16:35:11
Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can sup...
CVE-2018-25122
- EPSS 1.24%
- Veröffentlicht 30.10.2025 21:37:48
- Zuletzt bearbeitet 05.11.2025 18:26:50
Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output e...
CVE-2024-14005
- EPSS 0.59%
- Veröffentlicht 30.10.2025 21:37:28
- Zuletzt bearbeitet 06.11.2025 16:36:47
Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that are incorporat...
CVE-2020-36867
- EPSS 1.35%
- Veröffentlicht 30.10.2025 21:37:09
- Zuletzt bearbeitet 05.11.2025 18:23:27
Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insuff...
CVE-2021-47689
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:36:50
- Zuletzt bearbeitet 06.11.2025 18:20:38
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting (XSS) vulnerability in the Templates pages, specifically in the UI logic that renders and handles the Active/Actions buttons. Insu...
CVE-2021-47691
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:36:28
- Zuletzt bearbeitet 06.11.2025 18:20:26
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities via the Services page affecting the config_name and service_description fields. Insufficient validat...
CVE-2022-50584
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:36:08
- Zuletzt bearbeitet 06.11.2025 18:19:44
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the search and deletion interfaces. Insufficient validation or escaping of user-supplied input may allow ...