xi vulnerabilities
CVEs whose affected-version data names the xi package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2023-24035Low· 3.5An issue was discovered in Nagios XI before 5.9.3
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in t…
▾ SunlitNagios · Nagios XIEPSS 0.77%via NVD
CVE-2023-24034Low· 3.1An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3
An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
▾ SunlitNagios · Nagios XIEPSS 0.53%via NVD