nagios

301 tracked vulnerabilities.

CVE-2024-13993 MEDIUM
Nagios XI < 2024R1.1.2 - Reflected Cross-Site Scripting via Login Page
Oct 30, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-13986 HIGH
Nagios XI < 2024R1.3.2 - Authenticated Remote Code Execution via MIB Upload and Snapshot Rename
Aug 28, 2025
CVSS 8.8
EPSS 0.02
CVE-2024-54957 MEDIUM
Nagios XI 2024R1.2.2 - Open Redirect via Tools Page
Feb 27, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-54961 MEDIUM
Nagios XI 2024R1.2.2 - Unauthenticated Exposure of Sensitive User Information
Feb 20, 2025
CVSS 6.5
EPSS 0.01
CVE-2024-54960 MEDIUM
Nagios XI 2024R1.2.2 - SQL Injection via History Tab Component
Feb 20, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-54959 MEDIUM
Nagios XI 2024R1.2.2 - Cross-Site Request Forgery and Cross-Site Scripting via Favorites Component
Feb 20, 2025
CVSS 6.1
EPSS 0.00
CVE-2024-54958 MEDIUM
Nagios XI 2024R1.2.2 - Stored Cross-Site Scripting in Tools Page
Feb 20, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-42898 MEDIUM
Nagios XI 2024R1.1.4 - Stored Cross-Site Scripting via Account Settings Name Parameter
Jan 09, 2025
CVSS 5.4
EPSS 0.03
CVE-2024-43199 HIGH
Nagios NDOUtils <2.1.4 - Privilege Escalation
Aug 07, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-33775 CRITICAL
Nagios XI 2024R1.01 - Privilege Escalation via Autodiscover Dashlet
May 01, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-24402 CRITICAL
Nagios XI 2024R1.01 - Privilege Escalation via npcd Script Injection
Feb 26, 2024
CVSS 9.8
EPSS 0.21
CVE-2024-24401 CRITICAL
Nagios XI 2024R1.01 - SQL Injection via monitoringwizard.php
Feb 26, 2024
CVSS 9.8
EPSS 0.58
CVE-2023-7323 MEDIUM
Nagios Log Server < 2024 - Cross-Site Scripting via Create User Function
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7322 HIGH
Nagios Log Server < 2024 - Incorrect Authorization Granting Full API Access
Oct 30, 2025
CVSS 8.1
EPSS 0.00
CVE-2023-7321 MEDIUM
Nagios Log Server < 2.1.14 - Cross-Site Scripting via Snapshots Page
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7319 MEDIUM
Nagios Network Analyzer < 2024R1 - Cross-Site Scripting via Percentile Calculator Menu
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7318 MEDIUM
Nagios XI < 2024R1.0.2 - Cross-Site Scripting via Core Command Expansion Page
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2023-7317 HIGH
Nagios XI < 2024R1 - Missing Authorization in Web SSH Terminal
Oct 30, 2025
CVSS 8.8
EPSS 0.00
CVE-2023-7316 MEDIUM
Nagios XI < 2024R1 - Cross-Site Scripting via Graph Explorer
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2023-7315 MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting via Graph Explorer
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7314 MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting via Bandwidth Report
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7313 MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting via Bulk Modifications Tool
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7312 MEDIUM
Nagios Fusion < 4.2.0 - Stored Cross-Site Scripting in Email Settings
Oct 30, 2025
CVSS 4.8
EPSS 0.00
CVE-2023-53690 MEDIUM
Nagios Fusion < 4.2.0 - Stored Cross-Site Scripting in LDAP/AD Authentication-Server Configuration
Oct 30, 2025
CVSS 4.8
EPSS 0.01
CVE-2023-53689 MEDIUM
Nagios Fusion < 4.2.0 - Reflected Cross-Site Scripting in License Key Configuration
Oct 30, 2025
CVSS 4.8
EPSS 0.00