9.4

CVSS4.0

CVE-2023-7317 - Nagios XI < 2024R1 Web SSH Terminal Missing Access Control

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of s…

📅 Published: Oct. 30, 2025, 9:47 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:22 p.m.

8.7

CVSS4.0

CVE-2020-36863 - Nagios XI < 5.7.2 Unrestricted File Upload via Audio Import Directory

Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file types or enforce storage outside of the webroot, and the web server permitted execution within the upload directory. An a…

📅 Published: Oct. 30, 2025, 9:46 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:24 p.m.

6.9

CVSS4.0

CVE-2020-36862 - Nagios XI < 5.6.11 Unauthenticated XSS and SSRF via Highcharts

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch attacker-specified URLs (SSR…

📅 Published: Oct. 30, 2025, 9:46 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:24 p.m.

5.1

CVSS4.0

CVE-2022-50587 - Nagios XI < 5.8.9 Stored XSS via Command Names in Apply Config Error Text

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:46 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2022-50586 - Nagios XI < 5.8.9 Stored XSS via BPI Info URL

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:45 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:22 p.m.

5.1

CVSS4.0

CVE-2022-50588 - Nagios XI < 5.8.9 Stored XSS in Update Checking

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:45 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:21 p.m.

8.7

CVSS4.0

CVE-2020-36869 - Nagios XI < 5.7.5 SQL injection via SNMP Trap Interface Edit Page

Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized…

📅 Published: Oct. 30, 2025, 9:45 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:23 p.m.

8.7

CVSS4.0

CVE-2016-15050 - Nagios XI < 5.2.4 SQL Injection in Notification Search

Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statements without adequate parameterization or sanitation, allowing an authenticated user to manipulate database queries. Suc…

📅 Published: Oct. 30, 2025, 9:44 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:27 p.m.

9.2

CVSS4.0

CVE-2024-13996 - Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session ex…

📅 Published: Oct. 30, 2025, 9:44 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:17 p.m.

5.1

CVSS4.0

CVE-2024-13993 - Nagios XI < 2024R1.1.2 Reflected XSS via Login Page on Older Browsers

Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a malicious link that, wh…

📅 Published: Oct. 30, 2025, 9:43 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:18 p.m.
Total resulsts: 317894
Page 149 of 31,790
« previous page » next page
Filters