CVE-2022-50585
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:34:05
- Zuletzt bearbeitet 06.11.2025 18:19:25
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.7 / Nagios XI 5.8.9 contains a cross-site scripting (XSS) vulnerability via the Audit Log page search input. Insufficient validation or escaping of user-supplied input may allow an ...
CVE-2020-36859
- EPSS 1.49%
- Veröffentlicht 30.10.2025 21:33:40
- Zuletzt bearbeitet 06.11.2025 18:20:58
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user-supplied input was incorporated into SQL queries used by configuration...
CVE-2021-47693
- EPSS 1.49%
- Veröffentlicht 30.10.2025 21:33:18
- Zuletzt bearbeitet 06.11.2025 18:19:57
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search text handling. Unsanitized user-supplied input was incorporated into SQL queries used by configuration objec...
CVE-2021-47694
- EPSS 0.68%
- Veröffentlicht 30.10.2025 21:32:43
- Zuletzt bearbeitet 06.11.2025 18:19:35
The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may ...
CVE-2013-10073
- EPSS 2.09%
- Veröffentlicht 30.10.2025 21:32:22
- Zuletzt bearbeitet 06.11.2025 16:24:10
Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to...
CVE-2013-10072
- EPSS 0.16%
- Veröffentlicht 30.10.2025 21:32:02
- Zuletzt bearbeitet 06.11.2025 15:17:13
Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery re...
CVE-2020-36857
- EPSS 0.41%
- Veröffentlicht 30.10.2025 21:31:41
- Zuletzt bearbeitet 05.11.2025 18:25:26
Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative...
CVE-2012-10063
- EPSS 1.49%
- Veröffentlicht 30.10.2025 21:31:21
- Zuletzt bearbeitet 06.11.2025 15:09:58
Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially a...
CVE-2020-36856
- EPSS 0.32%
- Veröffentlicht 30.10.2025 21:30:59
- Zuletzt bearbeitet 05.11.2025 18:26:02
Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Mana...
CVE-2024-14002
- EPSS 0.74%
- Veröffentlicht 30.10.2025 21:30:39
- Zuletzt bearbeitet 06.11.2025 16:23:37
Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive in...