Nagios

Nagios Core

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 12.08.2026 16:48:27
  • Zuletzt bearbeitet 12.08.2026 18:17:30

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCO...

  • EPSS 0.52%
  • Veröffentlicht 12.08.2026 16:46:35
  • Zuletzt bearbeitet 12.08.2026 20:17:44

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or c...

  • EPSS 0.17%
  • Veröffentlicht 12.08.2026 16:34:33
  • Zuletzt bearbeitet 12.08.2026 17:17:27

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization, allowing attackers to ...

  • EPSS 0.17%
  • Veröffentlicht 12.08.2026 16:32:16
  • Zuletzt bearbeitet 13.08.2026 17:17:22

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, en...

  • EPSS 0.27%
  • Veröffentlicht 12.08.2026 16:30:02
  • Zuletzt bearbeitet 12.08.2026 19:17:34

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated use...

  • EPSS 2.3%
  • Veröffentlicht 23.12.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:07

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.

Exploit
  • EPSS 2.55%
  • Veröffentlicht 17.12.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:55:34

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

Exploit
  • EPSS 4.51%
  • Veröffentlicht 12.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:47:07

qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

Exploit
  • EPSS 4.51%
  • Veröffentlicht 12.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:47:07

qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

  • EPSS 0.33%
  • Veröffentlicht 11.09.2017 22:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users to ga...