CVE-2023-7319
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:28:29
- Zuletzt bearbeitet 07.11.2025 19:15:44
Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script ...
CVE-2025-34278
- EPSS 0.62%
- Veröffentlicht 30.10.2025 21:28:11
- Zuletzt bearbeitet 06.11.2025 18:15:26
Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later...
CVE-2025-34280
- EPSS 0.51%
- Veröffentlicht 30.10.2025 21:27:41
- Zuletzt bearbeitet 06.11.2025 18:15:09
Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigg...
CVE-2025-28059
- EPSS 0.17%
- Veröffentlicht 18.04.2025 00:00:00
- Zuletzt bearbeitet 11.07.2025 13:33:38
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend f...
CVE-2025-28131
- EPSS 0.04%
- Veröffentlicht 01.04.2025 17:15:46
- Zuletzt bearbeitet 11.07.2025 13:39:20
A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with "Read-Only" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due...
CVE-2025-28132
- EPSS 0.04%
- Veröffentlicht 01.04.2025 17:15:46
- Zuletzt bearbeitet 18.06.2025 13:59:16
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where sess...
CVE-2021-28924
- EPSS 66.18%
- Veröffentlicht 08.04.2021 13:15:14
- Zuletzt bearbeitet 21.11.2024 06:00:23
Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
CVE-2021-28925
- EPSS 74.24%
- Veröffentlicht 08.04.2021 13:15:14
- Zuletzt bearbeitet 21.11.2024 06:00:24
SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.