Search: "nagios"

320 CVEs found

CVE-2025-34283
6.5 MEDIUM

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user...

Published: 2025-10-30
Products: 20
Vendors:
nagios

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject sh...

Published: 2025-10-30
Products: 23
Vendors:
nagios

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backe...

Published: 2025-10-30
Products: 1
Vendors:
nagios

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by ww...

Published: 2025-10-30
Products: 23
Vendors:
nagios

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insuf...

Published: 2025-10-30
Products: 8
Vendors:
nagios
CVE-2024-13992
5.4 MEDIUM

Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable compon...

Published: 2025-10-31
Products: 4
Vendors:
nagios
CVE-2021-47698
5.4 MEDIUM

Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of...

Published: 2025-11-03
Products: 1
Vendors:
nagios

Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the u...

Published: 2025-11-03
Products: 7
Vendors:
nagios
CVE-2024-13998
6.5 MEDIUM

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have ac...

Published: 2025-11-03
Products: 7
Vendors:
nagios

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain...

Published: 2025-11-17
Products: 2
Vendors:
nagios

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' use...

Published: 2025-11-17
Products: 2
Vendors:
nagios
CVE-2025-34288
6.7 MEDIUM

Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance ...

Published: 2025-12-16
Products: 3
Vendors:
nagios
CVE-2023-53948
9.8 CRITICAL

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input ...

Published: 2025-12-19
Products: 0

NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.

Published: 2025-12-29
Products: 1
Vendors:
nagios

In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.

Published: 2025-12-29
Products: 1
Vendors:
nagios

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearma...

Published: 2026-02-20
Products: 1
Vendors:
it-novum

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP dese...

Published: 2026-02-20
Products: 1
Vendors:
it-novum

Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagio...

Published: 2026-02-20
Products: 1
Vendors:
nagios

Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authe...

Published: 2026-02-20
Products: 1
Vendors:
nagios

Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o...

Published: 2026-02-20
Products: 1
Vendors:
nagios