9.4

CVSS4.0

CVE-2020-36856 - Nagios XI < 5.6.14 Authenticated RCE command_test.php via address

Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Manager to inject shell metacharacters that are incor…

📅 Published: Oct. 30, 2025, 9:30 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:26 p.m.

7.1

CVSS4.0

CVE-2024-14002 - Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis

Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host.

📅 Published: Oct. 30, 2025, 9:30 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:23 p.m.

9.4

CVSS4.0

CVE-2025-34284 - Nagios XI < 2024R2 Authenticated Command Injection via WinRM Plugin

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation …

📅 Published: Oct. 30, 2025, 9:30 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:14 p.m.

7.1

CVSS4.0

CVE-2024-13995 - Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compr…

📅 Published: Oct. 30, 2025, 9:29 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:17 p.m.

7.1

CVSS4.0

CVE-2025-34283 - Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.

📅 Published: Oct. 30, 2025, 9:29 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:14 p.m.

8.7

CVSS4.0

CVE-2024-13994 - Nagios XI < 2024R1.1.2 Allow Insecure Logins Missing Authorization

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, priv…

📅 Published: Oct. 30, 2025, 9:29 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:18 p.m.

7.3

CVSS4.0

CVE-2024-13999 - Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromi…

📅 Published: Oct. 30, 2025, 9:28 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:15 p.m.

5.1

CVSS4.0

CVE-2023-7319 - Nagios Network Analyzer < 2024R1 XSS via Percentile Calculator Menu

Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:28 p.m. 🔄 Last Modified: Nov. 7, 2025, 7:15 p.m.

5.1

CVSS4.0

CVE-2025-34278 - Nagios Network Analyzer < 2024R1 Source Groups / Percentile Calculator Menu Stored XSS

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a v…

📅 Published: Oct. 30, 2025, 9:28 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:15 p.m.

8.6

CVSS4.0

CVE-2025-34280 - Nagios Network Analyzer < 2024R2.0.1 RCE in LDAP Certificate Removal Function

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in th…

📅 Published: Oct. 30, 2025, 9:27 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:15 p.m.
Total resulsts: 318408
Page 204 of 31,841
« previous page » next page
Filters