nagios

301 tracked vulnerabilities.

CVE-2023-53688 MEDIUM
Nagios XI < 5.11.3 - Cross-Site Scripting and Cross-Site Request Forgery via Hypermap Replay
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2023-48082 CRITICAL
Nagios XI < 2024R1 - API Key Generation Weakness
Oct 14, 2024
CVSS 9.1
EPSS 0.01
CVE-2023-51072 MEDIUM
Nagios XI <= 2024R1 - Authenticated Stored Cross-Site Scripting via NOC Audio File Upload
Feb 02, 2024
CVSS 5.4
EPSS 0.02
CVE-2023-48085 CRITICAL
Nagios XI < 5.11.3 - Remote Code Execution via command_test.php
Dec 14, 2023
CVSS 9.8
EPSS 0.62
CVE-2023-48084 CRITICAL NUCLEI
Nagios XI < 5.11.3 - SQL Injection via Bulk Modification Tool
Dec 14, 2023
CVSS 9.8
EPSS 0.82
CVE-2023-40934 HIGH
Nagios XI < 5.11.2 - Authenticated SQL Injection via Host Escalation Notification Settings
Sep 19, 2023
CVSS 7.2
EPSS 0.01
CVE-2023-40933 HIGH
Nagios XI < 5.11.2 - Authenticated SQL Injection via ID Parameter in update_banner_message()
Sep 19, 2023
CVSS 8.8
EPSS 0.18
CVE-2023-40932 MEDIUM
Nagios XI < 5.11.2 - Authenticated Stored Cross-Site Scripting via Custom Logo Alt-Text Field
Sep 19, 2023
CVSS 5.4
EPSS 0.03
CVE-2023-40931 MEDIUM NUCLEI
Nagios XI 5.11.0-5.11.1 - Authenticated SQL Injection via Banner Message ID Parameter
Sep 19, 2023
CVSS 6.5
EPSS 0.88
CVE-2022-50588 MEDIUM
Nagios XI < 5.8.9 - Stored Cross-Site Scripting in Update Checking Feature
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2022-50587 MEDIUM
Nagios XI < 5.8.9 - Stored Cross-Site Scripting via Apply Configuration Error Text
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2022-50586 MEDIUM
Nagios XI < 5.8.9 - Stored Cross-Site Scripting via BPI Info URL Field
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2022-50585 MEDIUM
Nagios XI < 5.8.9 - Cross-Site Scripting via Audit Log Page Search Input
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2022-50584 MEDIUM
Nagios XI < 5.8.8 - Cross-Site Scripting in Core Config Manager Search and Deletion Interfaces
Oct 30, 2025
CVSS 5.4
EPSS 0.00
CVE-2022-38254 MEDIUM
Nagios XI < 5.8.7 - Cross-Site Scripting via ajax.php in CCM
Sep 07, 2022
CVSS 6.1
EPSS 0.34
CVE-2022-38251 MEDIUM
Nagios XI 5.8.6 - Stored Cross-Site Scripting via System Performance Settings Page
Sep 07, 2022
CVSS 4.8
EPSS 0.36
CVE-2022-38250 CRITICAL
Nagios XI 5.8.6 - SQL Injection via MIB Name Parameter
Sep 07, 2022
CVSS 9.8
EPSS 0.44
CVE-2022-38249 MEDIUM
Nagios XI 5.8.6 - Stored Cross-Site Scripting via MTR Component
Sep 07, 2022
CVSS 6.1
EPSS 0.34
CVE-2022-38248 MEDIUM
Nagios XI < 5.8.7 - Cross-Site Scripting in auditlog.php
Sep 07, 2022
CVSS 6.1
EPSS 0.34
CVE-2022-38247 MEDIUM
Nagios XI 5.8.6 - Stored Cross-Site Scripting via System Settings Page
Sep 07, 2022
CVSS 4.8
EPSS 0.34
CVE-2022-29272 MEDIUM NUCLEI
Nagios XI <= 5.8.5 - Open Redirect via Login Function
Jun 29, 2022
CVSS 6.1
EPSS 0.04
CVE-2022-29271 MEDIUM
Nagios XI <5.8.5 - Privilege Escalation
Jun 29, 2022
CVSS 6.5
EPSS 0.01
CVE-2022-29270 MEDIUM
Nagios XI <= 5.8.5 - Unauthenticated Email Address Change
Jun 29, 2022
CVSS 4.3
EPSS 0.01
CVE-2022-29269 MEDIUM
Nagios XI <= 5.8.5 - Authenticated Cross-Site Scripting in Schedule Report Function
Jun 29, 2022
CVSS 6.5
EPSS 0.05
CVE-2021-47698 MEDIUM
Nagios XI < 5.8.7 - Cross-Site Scripting via Core UI Views URL Handling
Nov 03, 2025
CVSS 5.4
EPSS 0.00