All vulnerabilities
194 / 194
Sort
6.1
CVE-2021-25299CVE
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists …
2021-01-01Pre-auth
EPSS96.9%
pct 99
9.8
CVE-2018-15708CVE
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary comm…
2018-01-01Pre-auth
EPSS89.4%
pct 99
5.4
CVE-2021-38156CVE
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative…
2021-01-01
EPSS88.9%
pct 99
5.4
CVE-2020-27988CVE
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
2020-01-01
EPSS87.2%
pct 99
7.2
CVE-2020-35578CVE
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-…
2020-01-01
EPSS81.9%
pct 99
9.8
CVE-2021-37350CVE
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modificatio…
2021-01-01Pre-auth
EPSS80.0%
pct 99
7.2
CVE-2020-5791CVE
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a r…
2020-01-01
EPSS78.6%
pct 99
8.8
CVE-2019-15949CVE KEV
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to …
2019-01-01KEV
EPSS77.7%
pct 99
9.8
CVE-2023-48085CVE
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnera…
2023-01-01Pre-auth
EPSS75.8%
pct 99
8.8
CVE-2021-25298CVE KEV
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the…
2021-01-01KEV
EPSS75.2%
pct 99
8.8
CVE-2026-2043CVE
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulner…
2026-01-01
EPSS74.2%
pct 99
4.8
CVE-2020-10819CVE
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ username parameter.
2020-01-01
EPSS73.8%
pct 99
4.8
CVE-2020-10821CVE
Nagios XI 5.6.11 allows XSS via the account/main.php theme parameter.
2020-01-01
EPSS73.6%
pct 99
8.8
CVE-2021-25296CVE KEV
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the…
2021-01-01KEV
EPSS72.4%
pct 99
7.2
CVE-2021-40344CVE
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, …
2021-01-01
EPSS66.2%
pct 99
8.8
CVE-2018-8735CVE
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 all…
2018-01-01
EPSS64.6%
pct 99
7.2
CVE-2020-5792CVE
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote,…
2020-01-01
EPSS61.0%
pct 99
6.1
CVE-2020-15902CVE
Graph Explorer in Nagios XI before 5.7.2 allows XSS via the link url option.
2020-01-01Pre-auth
EPSS56.3%
pct 98
7.2
CVE-2021-3277CVE
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improp…
2021-01-01
EPSS54.6%
pct 98
9.8
CVE-2018-8734CVE
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before …
2018-01-01Pre-auth
EPSS53.7%
pct 98
6.1
CVE-2018-15712CVE
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via…
2018-01-01Pre-auth
EPSS48.6%
pct 98
8.8
CVE-2018-8736CVE
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an a…
2018-01-01
EPSS47.4%
pct 98
8.8
CVE-2019-9164CVE
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary…
2019-01-01
EPSS46.0%
pct 98
7.8
CVE-2018-15710CVE
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodis…
2018-01-01
EPSS44.1%
pct 98
7.2
CVE-2018-10738CVE
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php ch…
2018-01-01
EPSS42.6%
pct 98
7.2
CVE-2018-10737CVE
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSe…
2018-01-01
EPSS42.6%
pct 98
7.2
CVE-2018-10736CVE
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 par…
2018-01-01
EPSS42.6%
pct 98
7.2
CVE-2018-10735CVE
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php c…
2018-01-01
EPSS42.6%
pct 98
8.8
CVE-2021-25297CVE KEV
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the…
2021-01-01KEV
EPSS40.6%
pct 98
9.8
CVE-2024-24401CVE
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrar…
2024-01-01Pre-auth
EPSS40.1%
pct 98
6.5
CVE-2018-10553CVE
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory travers…
2018-01-01
EPSS39.5%
pct 98
8.8
CVE-2020-15901CVE
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbi…
2020-01-01
EPSS38.5%
pct 98
8.8
CVE-2018-15711CVE
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of mo…
2018-01-01
EPSS36.0%
pct 98
9.8
CVE-2023-48084CVE
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the…
2023-01-01Pre-auth
EPSS33.7%
pct 98
4.8
CVE-2020-10820CVE
Nagios XI 5.6.11 allows XSS via the includes/components/ldap_ad_integration/ password parameter.
2020-01-01
EPSS30.1%
pct 97
9.8
CVE-2018-8733CVE
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x…
2018-01-01Pre-auth
EPSS28.5%
pct 97
8.6
CVE-2025-34227ANC
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the…
2025-01-01
EPSS26.2%
pct 97
5.4
CVE-2019-20139CVE
In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parame…
2019-01-01
EPSS26.1%
pct 97
8.8
CVE-2021-37343CVE
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component …
2021-01-01
EPSS23.8%
pct 97
7.2
CVE-2021-40345CVE
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, …
2021-01-01
EPSS23.0%
pct 97
Select a vulnerability on the left to open the preview.