nagios
301 tracked vulnerabilities.
CVE-2016-15051
MEDIUM
Nagios XI < 5.2.4 - Cross-Site Scripting via Reports Startdate and Enddate Fields
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2016-15050
HIGH
Nagios XI < 5.2.4 - Authenticated SQL Injection in Notification Search
Oct 30, 2025
CVSS 8.8
EPSS 0.01
CVE-2016-15049
MEDIUM
Nagios Log Server < 1.4.2 - Stored Cross-Site Scripting in Dashboards Logs Table
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2016-8641
MEDIUM
Nagios 4.2.x - Privilege Escalation
Aug 01, 2018
CVSS 6.7
EPSS 0.01
CVE-2016-0726
CRITICAL
Nagios - Use of Hard-coded Credentials
Jun 06, 2017
CVSS 9.8
EPSS 0.00
CVE-2016-6209
MEDIUM
Nagios - Cross-Site Scripting
Mar 31, 2017
CVSS 6.1
EPSS 0.01
CVE-2016-10089
HIGH
Nagios <4.3.2 - Privilege Escalation
Feb 15, 2017
CVSS 7.8
EPSS 0.00
CVE-2016-9566
HIGH
Nagios < 4.2.3 - Privilege Escalation via Symlink Attack on Log File
Dec 15, 2016
CVSS 7.8
EPSS 0.04
CVE-2016-9565
CRITICAL
Nagios < 4.2.1 - Arbitrary File Read and Write via Spoofed RSS Feed Response
Dec 15, 2016
CVSS 9.8
EPSS 0.21
CVE-2015-3618
MEDIUM
Nagios Business Process Intelligence < 2.3.4 - Cross-Site Scripting via index.php
Feb 06, 2018
CVSS 6.1
EPSS 0.03
CVE-2014-5009
CRITICAL
snoopy - Remote Command Execution
Mar 31, 2017
CVSS 9.8
EPSS 0.02
CVE-2014-4703
Nagios Plugins <2.0.2 - Info Disclosure
Dec 05, 2014
EPSS 0.00
CVE-2014-4702
Nagios Plugins <2.0.2 - Info Disclosure
Dec 05, 2014
EPSS 0.00
CVE-2014-4701
Nagios Plugins <2.0.2 - Info Disclosure
Dec 05, 2014
EPSS 0.00
CVE-2014-2913
Nagios Remote Plugin Executor <2.15 - RCE
May 07, 2014
EPSS 0.19
CVE-2014-1878
Icinga < 1.8.5 and Nagios < 4.0.3 - Stack-based Buffer Overflow via Long Message to cmd.cgi
Feb 28, 2014
EPSS 0.02
CVE-2013-10074
MEDIUM
Nagios XI < 2012R2.6 - Cross-Site Scripting via Tools Menu
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2013-10073
HIGH
Nagios XI <2012R1.6 - Command Injection
Oct 30, 2025
CVSS 8.8
EPSS 0.01
CVE-2013-10072
MEDIUM
Nagios XI < 2012R1.6 - Missing Authorization in Auto-Discovery
Oct 30, 2025
CVSS 6.5
EPSS 0.00
CVE-2013-10071
MEDIUM
Nagios XI < 2012R1.6 - Reflected Cross-Site Scripting via Dashboard Dashlet AJAX Load Functionality
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2013-4215
Nagios Plugins 1.4.16 - Privilege Escalation via Symlink Attack on /tmp/ipxping/ipxping
May 05, 2014
EPSS 0.00
CVE-2013-2214
Nagios 3.x < 3.5.1 and 4.0 < beta4 - Authenticated Information Disclosure via status.cgi
Feb 10, 2014
EPSS 0.03
CVE-2013-7205
Nagios Core <4.0.2 - Info Disclosure
Jan 15, 2014
EPSS 0.02
CVE-2013-7108
Nagios Core <4.0.2 - Info Disclosure
Jan 15, 2014
EPSS 0.49
CVE-2013-6875
Nagios XI < 2012r2.4 - SQL Injection via tfPassword Parameter
Nov 26, 2013
EPSS 0.20
Products
nagios_xi 192
nagios 37
log_server 23
fusion 19
network_analyzer 7
nagios_core 5
XI 3
incident_manager 3
plugins 3
remote_plug_in_executor 3
Log Server 2
Nagios XI 2
favorites 2
nagios_cross_platform_agent 2
business_process_intelligence 1
nagios_network_analyzer 1
nagios_xi_docker_wizard 1
nagios_xi_switch_wizard 1
nagios_xi_watchguard_wizard 1
ndoutils 1
remote_plugin_executor 1
Quick Filters