8.7

CVSS4.0

CVE-2021-47693 - Nagios XI < 5.8.5 Core Config Manager (CCM) SQL Injection via Improper Escaping in Search Text

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search text handling. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing authenticated users to inject…

📅 Published: Oct. 30, 2025, 9:33 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:19 p.m.

5.1

CVSS4.0

CVE-2021-47694 - Nagios XI < 5.8.6 Core Config Manager (CCM) Reflected XSS via Test Command

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary…

📅 Published: Oct. 30, 2025, 9:32 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:19 p.m.

8.7

CVSS4.0

CVE-2013-10073 - Nagios XI < 2012R1.6 Auto-Discovery Shell Command Injection

Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to discovery functionality to execute arbitrary com…

📅 Published: Oct. 30, 2025, 9:32 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:24 p.m.

7.2

CVSS4.0

CVE-2013-10072 - Nagios XI < 2012R1.6 Auto-Discovery Missing Authorization

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing unintended access to discovery…

📅 Published: Oct. 30, 2025, 9:32 p.m. 🔄 Last Modified: Nov. 6, 2025, 3:17 p.m.

8.6

CVSS4.0

CVE-2020-36857 - Nagios XI < 5.6.14 Authenticated SQL Injection via SNMP Trap Interface Page

Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not pr…

📅 Published: Oct. 30, 2025, 9:31 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:25 p.m.

8.7

CVSS4.0

CVE-2012-10063 - Nagios XI < 2012R1.3 Authenticated SQL Injection in Legacy CCM

Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to configuration data stored in th…

📅 Published: Oct. 30, 2025, 9:31 p.m. 🔄 Last Modified: Nov. 6, 2025, 3:09 p.m.

9.4

CVSS4.0

CVE-2020-36856 - Nagios XI < 5.6.14 Authenticated RCE command_test.php via address

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Manager to inject shell metacharacters that are incor…

📅 Published: Oct. 30, 2025, 9:30 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:26 p.m.

7.1

CVSS4.0

CVE-2024-14002 - Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis

Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host.

📅 Published: Oct. 30, 2025, 9:30 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:23 p.m.

9.4

CVSS4.0

CVE-2025-34284 - Nagios XI < 2024R2 Authenticated Command Injection via WinRM Plugin

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation …

📅 Published: Oct. 30, 2025, 9:30 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:14 p.m.

7.1

CVSS4.0

CVE-2024-13995 - Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compr…

📅 Published: Oct. 30, 2025, 9:29 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:17 p.m.
Total resulsts: 318404
Page 203 of 31,841
« previous page » next page
Filters