Skip to main content

Vendor/product archive

nagios / nagios_xi CVEs

Beta · best-effort

194 CVEs tagged to nagios / nagios_xi33 Critical, 70 High, 91 Medium, 0 Low, 0 Unrated.

CVE-2026-2043

Published Feb 20, 2026

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-2042

Published Feb 20, 2026

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-2041

Published Feb 20, 2026

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected i…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-67255

Published Dec 29, 2025

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67254

Published Dec 29, 2025

NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-34288

Published Dec 16, 2025

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑ac…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-13998

Published Nov 3, 2025

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users w…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13997

Published Nov 3, 2025

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain roo…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-47698

Published Nov 3, 2025

Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient vali…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13992

Published Oct 31, 2025

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website.…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34287

Published Oct 30, 2025

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the fi…

CVSS 8.4 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-34286

Published Oct 30, 2025

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameter…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-34284

Published Oct 30, 2025

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated admin…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-34283

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges co…

CVSS 7.1 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-34135

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permi…

CVSS 5.1 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-34134

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2024-14009

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/con…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-14008

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-14006

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs wit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-14005

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authent…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-14004

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate Na…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-14003

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbou…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-14002

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cau…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-14001

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplie…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-14000

Published Oct 30, 2025

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplie…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 194 CVEsPage 1 of 8