nagios

301 tracked vulnerabilities.

CVE-2016-15051 MEDIUM
Nagios XI < 5.2.4 - Cross-Site Scripting via Reports Startdate and Enddate Fields
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2016-15050 HIGH
Nagios XI < 5.2.4 - Authenticated SQL Injection in Notification Search
Oct 30, 2025
CVSS 8.8
EPSS 0.01
CVE-2016-15049 MEDIUM
Nagios Log Server < 1.4.2 - Stored Cross-Site Scripting in Dashboards Logs Table
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2016-8641 MEDIUM
Nagios 4.2.x - Privilege Escalation
Aug 01, 2018
CVSS 6.7
EPSS 0.01
CVE-2016-0726 CRITICAL
Nagios - Use of Hard-coded Credentials
Jun 06, 2017
CVSS 9.8
EPSS 0.00
CVE-2016-6209 MEDIUM
Nagios - Cross-Site Scripting
Mar 31, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-10089 HIGH
Nagios <4.3.2 - Privilege Escalation
Feb 15, 2017
CVSS 7.8
EPSS 0.00
CVE-2016-9566 HIGH
Nagios < 4.2.3 - Privilege Escalation via Symlink Attack on Log File
Dec 15, 2016
CVSS 7.8
EPSS 0.04
CVE-2016-9565 CRITICAL
Nagios < 4.2.1 - Arbitrary File Read and Write via Spoofed RSS Feed Response
Dec 15, 2016
CVSS 9.8
EPSS 0.21
CVE-2015-3618 MEDIUM
Nagios Business Process Intelligence < 2.3.4 - Cross-Site Scripting via index.php
Feb 06, 2018
CVSS 6.1
EPSS 0.03
CVE-2014-5009 CRITICAL
snoopy - Remote Command Execution
Mar 31, 2017
CVSS 9.8
EPSS 0.02
CVE-2014-4703
Nagios Plugins <2.0.2 - Info Disclosure
Dec 05, 2014
EPSS 0.00
CVE-2014-4702
Nagios Plugins <2.0.2 - Info Disclosure
Dec 05, 2014
EPSS 0.00
CVE-2014-4701
Nagios Plugins <2.0.2 - Info Disclosure
Dec 05, 2014
EPSS 0.00
CVE-2014-2913
Nagios Remote Plugin Executor <2.15 - RCE
May 07, 2014
EPSS 0.19
CVE-2014-1878
Icinga < 1.8.5 and Nagios < 4.0.3 - Stack-based Buffer Overflow via Long Message to cmd.cgi
Feb 28, 2014
EPSS 0.02
CVE-2013-10074 MEDIUM
Nagios XI < 2012R2.6 - Cross-Site Scripting via Tools Menu
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2013-10073 HIGH
Nagios XI <2012R1.6 - Command Injection
Oct 30, 2025
CVSS 8.8
EPSS 0.01
CVE-2013-10072 MEDIUM
Nagios XI < 2012R1.6 - Missing Authorization in Auto-Discovery
Oct 30, 2025
CVSS 6.5
EPSS 0.00
CVE-2013-10071 MEDIUM
Nagios XI < 2012R1.6 - Reflected Cross-Site Scripting via Dashboard Dashlet AJAX Load Functionality
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2013-4215
Nagios Plugins 1.4.16 - Privilege Escalation via Symlink Attack on /tmp/ipxping/ipxping
May 05, 2014
EPSS 0.00
CVE-2013-2214
Nagios 3.x < 3.5.1 and 4.0 < beta4 - Authenticated Information Disclosure via status.cgi
Feb 10, 2014
EPSS 0.03
CVE-2013-7205
Nagios Core <4.0.2 - Info Disclosure
Jan 15, 2014
EPSS 0.02
CVE-2013-7108
Nagios Core <4.0.2 - Info Disclosure
Jan 15, 2014
EPSS 0.49
CVE-2013-6875
Nagios XI < 2012r2.4 - SQL Injection via tfPassword Parameter
Nov 26, 2013
EPSS 0.20