Skip to main content

Vendor/product archive

nagios / nagios_xi CVEs

Beta · best-effort

194 CVEs tagged to nagios / nagios_xi33 Critical, 70 High, 91 Medium, 0 Low, 0 Unrated.

CVE-2021-47690

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities in Overlay modals. Insufficie…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47689

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting (XSS) vulnerability in the Templates pages, specifically in…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36869

Published Oct 30, 2025

Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges to ac…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36868

Published Oct 30, 2025

Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routin…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36867

Published Oct 30, 2025

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeli…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36866

Published Oct 30, 2025

Nagios XI versions prior to 5.7.3 are vulnerable to cross-site scripting (XSS) via the Manage Users page of the Admin interface. Insufficient validation or escaping of user-suppli…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36865

Published Oct 30, 2025

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. Insu…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36864

Published Oct 30, 2025

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplie…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36863

Published Oct 30, 2025

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file t…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36862

Published Oct 30, 2025

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/re…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36861

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site scripting (XSS) vulnerabilities in the overlay UI elements an…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36860

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site scripting (XSS) vulnerabilities in the object edit pages. Ins…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-36859

Published Oct 30, 2025

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36857

Published Oct 30, 2025

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36856

Published Oct 30, 2025

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` par…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-25123

Published Oct 30, 2025

Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25122

Published Oct 30, 2025

Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2018-25121

Published Oct 30, 2025

Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of user-supplied input…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15053

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping of user-suppl…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15052

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or escaping of user-supplied input…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15051

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient validat…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-15050

Published Oct 30, 2025

Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statem…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2013-10074

Published Oct 30, 2025

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-supplied inp…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-10073

Published Oct 30, 2025

Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanita…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2013-10072

Published Oct 30, 2025

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints an…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 51-75 of 194 CVEsPage 3 of 8