VulnSea

nagios_xi vulnerabilities

CVEs whose affected-version data names the nagios_xi package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2023-7314Medium· 5.4
10mo ago

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script i…

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script i…

Sunlitnagios · nagios_xiEPSS 0.45%via NVD
CVE-2023-7313Medium· 5.4
10mo ago

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in t…

Sunlitnagios · nagios_xiEPSS 0.45%via NVD
CVE-2024-33775High· 8.8PoC
2y ago

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

Midnightnagios · nagios_xiEPSS 1.4%via NVD
CVE-2021-37223Medium· 6.5
4y ago

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php

Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI applicatio…

Sunlitnagios · nagios_xiEPSS 5.0%via NVD
CVE-2021-37345High· 7.8
5y ago

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.

Twilightnagios · nagios_xiEPSS 0.57%via NVD
CVE-2021-25298High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled …

Abyssalnagios · nagios_xiEPSS 75%via NVD
CVE-2021-25297High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled inpu…

Abyssalnagios · nagios_xiEPSS 57%via NVD
CVE-2021-25296High· 8.8CISA KEVPoC
5y ago

Nagios XI version xi-5.7.5 is affected by OS command injection

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-control…

Abyssalnagios · nagios_xiEPSS 72%via NVD
CVE-2021-25299Medium· 6.1PoC
5y ago

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when …

Twilightnagios · nagios_xiEPSS 98%via NVD
nagios_xi vulnerabilities (CVEs) · VulnSea