nagios
301 tracked vulnerabilities.
CVE-2024-13993
MEDIUM
Nagios XI < 2024R1.1.2 - Reflected Cross-Site Scripting via Login Page
Oct 30, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-13986
HIGH
Nagios XI < 2024R1.3.2 - Authenticated Remote Code Execution via MIB Upload and Snapshot Rename
Aug 28, 2025
CVSS 8.8
EPSS 0.02
CVE-2024-54957
MEDIUM
Nagios XI 2024R1.2.2 - Open Redirect via Tools Page
Feb 27, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-54961
MEDIUM
Nagios XI 2024R1.2.2 - Unauthenticated Exposure of Sensitive User Information
Feb 20, 2025
CVSS 6.5
EPSS 0.01
CVE-2024-54960
MEDIUM
Nagios XI 2024R1.2.2 - SQL Injection via History Tab Component
Feb 20, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-54959
MEDIUM
Nagios XI 2024R1.2.2 - Cross-Site Request Forgery and Cross-Site Scripting via Favorites Component
Feb 20, 2025
CVSS 6.1
EPSS 0.00
CVE-2024-54958
MEDIUM
Nagios XI 2024R1.2.2 - Stored Cross-Site Scripting in Tools Page
Feb 20, 2025
CVSS 6.1
EPSS 0.01
CVE-2024-42898
MEDIUM
Nagios XI 2024R1.1.4 - Stored Cross-Site Scripting via Account Settings Name Parameter
Jan 09, 2025
CVSS 5.4
EPSS 0.03
CVE-2024-43199
HIGH
Nagios NDOUtils <2.1.4 - Privilege Escalation
Aug 07, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-33775
CRITICAL
Nagios XI 2024R1.01 - Privilege Escalation via Autodiscover Dashlet
May 01, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-24402
CRITICAL
Nagios XI 2024R1.01 - Privilege Escalation via npcd Script Injection
Feb 26, 2024
CVSS 9.8
EPSS 0.21
CVE-2024-24401
CRITICAL
Nagios XI 2024R1.01 - SQL Injection via monitoringwizard.php
Feb 26, 2024
CVSS 9.8
EPSS 0.58
CVE-2023-7323
MEDIUM
Nagios Log Server < 2024 - Cross-Site Scripting via Create User Function
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7322
HIGH
Nagios Log Server < 2024 - Incorrect Authorization Granting Full API Access
Oct 30, 2025
CVSS 8.1
EPSS 0.00
CVE-2023-7321
MEDIUM
Nagios Log Server < 2.1.14 - Cross-Site Scripting via Snapshots Page
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7319
MEDIUM
Nagios Network Analyzer < 2024R1 - Cross-Site Scripting via Percentile Calculator Menu
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7318
MEDIUM
Nagios XI < 2024R1.0.2 - Cross-Site Scripting via Core Command Expansion Page
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2023-7317
HIGH
Nagios XI < 2024R1 - Missing Authorization in Web SSH Terminal
Oct 30, 2025
CVSS 8.8
EPSS 0.00
CVE-2023-7316
MEDIUM
Nagios XI < 2024R1 - Cross-Site Scripting via Graph Explorer
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2023-7315
MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting via Graph Explorer
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7314
MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting via Bandwidth Report
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7313
MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting via Bulk Modifications Tool
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-7312
MEDIUM
Nagios Fusion < 4.2.0 - Stored Cross-Site Scripting in Email Settings
Oct 30, 2025
CVSS 4.8
EPSS 0.00
CVE-2023-53690
MEDIUM
Nagios Fusion < 4.2.0 - Stored Cross-Site Scripting in LDAP/AD Authentication-Server Configuration
Oct 30, 2025
CVSS 4.8
EPSS 0.01
CVE-2023-53689
MEDIUM
Nagios Fusion < 4.2.0 - Reflected Cross-Site Scripting in License Key Configuration
Oct 30, 2025
CVSS 4.8
EPSS 0.00
Products
nagios_xi 192
nagios 37
log_server 23
fusion 19
network_analyzer 7
nagios_core 5
XI 3
incident_manager 3
plugins 3
remote_plug_in_executor 3
Log Server 2
Nagios XI 2
favorites 2
nagios_cross_platform_agent 2
business_process_intelligence 1
nagios_network_analyzer 1
nagios_xi_docker_wizard 1
nagios_xi_switch_wizard 1
nagios_xi_watchguard_wizard 1
ndoutils 1
remote_plugin_executor 1
Quick Filters