8.4

CVSS4.0

CVE-2025-34287 - Nagios XI < 2024R2 Privilege Escalation via process_perfdata.pl

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code…

📅 Published: Oct. 30, 2025, 9:39 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2025-34135 - Nagios XI < 2024R1.4.2 Overly Permissive Permissions on Systemd Unit Files

Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable permissions that were not required. Overly permissive permissions on service unit files can broaden local attack surface by e…

📅 Published: Oct. 30, 2025, 9:39 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

8.5

CVSS4.0

CVE-2021-47700 - Nagios XI < 5.8.7 Insecure Permissions on Highcharts Temporary Directory

Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code executio…

📅 Published: Oct. 30, 2025, 9:39 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

8.8

CVSS4.0

CVE-2024-14006 - Nagios XI < 2024R1.2.2 Host Header Injection

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to poison generated lin…

📅 Published: Oct. 30, 2025, 9:38 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

8.7

CVSS4.0

CVE-2018-25122 - Nagios XI < 5.4.13 Component Download Page RCE

Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output encoding, allowing an authenticated user to inject…

📅 Published: Oct. 30, 2025, 9:37 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

9.4

CVSS4.0

CVE-2024-14005 - Nagios XI < 2024R1.2 Command Injection via Docker Wizard

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful e…

📅 Published: Oct. 30, 2025, 9:37 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

8.7

CVSS4.0

CVE-2020-36867 - Nagios XI < 5.7.3 Command Injection in Report PDF Download

Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowin…

📅 Published: Oct. 30, 2025, 9:37 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2021-47689 - Nagios XI < 5.8.0 Core Config Manager (CCM) XSS via Templates Pages

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting (XSS) vulnerability in the Templates pages, specifically in the UI logic that renders and handles the Active/Actions buttons. Insufficient validation or escaping of user-supplied …

📅 Published: Oct. 30, 2025, 9:36 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2021-47691 - Nagios XI < 5.8.2 Core Config Manager (CCM) XSS via Services Page

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities via the Services page affecting the config_name and service_description fields. Insufficient validation or escaping of user-supplied input may allow …

📅 Published: Oct. 30, 2025, 9:36 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2022-50584 - Nagios XI < 5.8.8 Core Config Manager (CCM) XSS via Search & Deletion Flows

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the search and deletion interfaces. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary scrip…

📅 Published: Oct. 30, 2025, 9:36 p.m. 🔄 Last Modified: Nov. 17, 2025, 6:21 p.m.
Total resulsts: 349182
Page 3203 of 34,919
« previous page » next page
Filters