Nagios

Nagios Xi

192 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 30.10.2025 21:29:17
  • Zuletzt bearbeitet 06.11.2025 16:18:33

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. Thi...

  • EPSS 0.69%
  • Veröffentlicht 30.10.2025 21:28:50
  • Zuletzt bearbeitet 06.11.2025 16:15:10

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misu...

Exploit
  • EPSS 2.15%
  • Veröffentlicht 25.09.2025 17:15:38
  • Zuletzt bearbeitet 14.10.2025 19:53:44

Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provide...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 28.08.2025 15:49:46
  • Zuletzt bearbeitet 04.11.2025 23:15:33

Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a path traversal in the Core Config Snapshots interface. The issue arises from insufficient validation of file paths and extensi...

  • EPSS 0.38%
  • Veröffentlicht 26.08.2025 00:00:00
  • Zuletzt bearbeitet 09.09.2025 18:56:36

A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web comp...

  • EPSS 46.6%
  • Veröffentlicht 05.08.2025 20:15:33
  • Zuletzt bearbeitet 06.08.2025 16:15:27

Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code e...

  • EPSS 0.14%
  • Veröffentlicht 27.02.2025 20:16:01
  • Zuletzt bearbeitet 07.07.2025 17:49:10

Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without ...

  • EPSS 3.8%
  • Veröffentlicht 20.02.2025 18:15:25
  • Zuletzt bearbeitet 01.07.2025 15:02:14

Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other ...

  • EPSS 3.8%
  • Veröffentlicht 20.02.2025 18:15:25
  • Zuletzt bearbeitet 01.07.2025 15:02:21

Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).

  • EPSS 2.37%
  • Veröffentlicht 20.02.2025 18:15:25
  • Zuletzt bearbeitet 07.07.2025 17:46:10

A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.