nagios
301 tracked vulnerabilities.
CVE-2021-37351
MEDIUM
Nagios XI < 5.8.5 - Unauthenticated Access to Guarded Pages via Crafted HTTP Request
Aug 13, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-37350
CRITICAL
Nagios XI < 5.8.5 - SQL Injection via Bulk Modifications Tool
Aug 13, 2021
CVSS 9.8
EPSS 0.41
CVE-2021-37349
HIGH
Nagios XI < 5.8.5 - Local Privilege Escalation via cleaner.php Database Input
Aug 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-37348
HIGH
Nagios XI < 5.8.5 - Local File Inclusion via index.php
Aug 13, 2021
CVSS 7.5
EPSS 0.12
CVE-2021-37347
HIGH
Nagios XI < 5.8.5 - Local Privilege Escalation via getprofile.sh Directory Argument
Aug 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-37346
CRITICAL
Nagios XI WatchGuard Wizard < 1.4.8 - Remote Code Execution via OS Command Injection
Aug 13, 2021
CVSS 9.8
EPSS 0.55
CVE-2021-37345
HIGH
Nagios XI < 5.8.5 - Local Privilege Escalation via xi-sys.cfg Import
Aug 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-37344
CRITICAL
Nagios XI Switch Wizard < 2.5.7 - Remote Code Execution via OS Command Injection
Aug 13, 2021
CVSS 9.8
EPSS 0.57
CVE-2021-37343
HIGH
Nagios XI Autodiscovery Webshell Upload
Aug 13, 2021
CVSS 8.8
EPSS 0.83
CVE-2021-35479
MEDIUM
Nagios Log Server < 2.1.9 - Stored Cross-Site Scripting via Custom Column View
Jul 30, 2021
CVSS 5.4
EPSS 0.48
CVE-2021-35478
MEDIUM
Nagios Log Server < 2.1.9 - Reflected Cross-Site Scripting via Alert History and Audit Log Dropdown
Jul 30, 2021
CVSS 5.4
EPSS 0.49
CVE-2021-3277
HIGH
Nagios XI < 5.7.5 - Authenticated Remote Code Execution via Custom-Includes Rename Functionality
Jun 07, 2021
CVSS 7.2
EPSS 0.35
CVE-2021-28925
CRITICAL
Nagios Network Analyzer < 2.4.3 - SQL Injection via o[col] Parameter
Apr 08, 2021
CVSS 9.8
EPSS 0.48
CVE-2021-28924
MEDIUM
Nagios Network Analyzer < 2.4.3 - Authenticated Cross-Site Scripting via Groups Queries Page
Apr 08, 2021
CVSS 6.1
EPSS 0.52
CVE-2021-3273
HIGH
Nagios XI < 5.7 - Authenticated Code Injection in graphtemplates.php
Feb 25, 2021
CVSS 7.2
EPSS 0.26
CVE-2021-25299
MEDIUM
NUCLEI
Nagios XI 5.7.5 - Stored Cross-Site Scripting in SSH Terminal Admin Page
Feb 15, 2021
CVSS 6.1
EPSS 0.85
CVE-2021-25298
HIGH
KEVNUCLEI
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
Feb 15, 2021
CVSS 8.8
EPSS 0.75
CVE-2021-25297
HIGH
KEVNUCLEI
Nagios XI xi-5.7.5 - Command Injection
Feb 15, 2021
CVSS 8.8
EPSS 0.82
CVE-2021-25296
HIGH
KEVNUCLEI
Nagios XI xi-5.7.5 - Command Injection
Feb 15, 2021
CVSS 8.8
EPSS 0.93
CVE-2021-26024
MEDIUM
Nagios XI Favorites < 1.0.2 - Insecure Direct Object Reference
Feb 03, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-26023
MEDIUM
Nagios Favorites < 1.0.2 - Cross-Site Scripting
Feb 03, 2021
CVSS 6.1
EPSS 0.38
CVE-2021-3193
CRITICAL
Nagios XI < 5.7.0 - Unauthenticated Remote Code Execution via Docker Config Wizard
Jan 26, 2021
CVSS 9.8
EPSS 0.25
CVE-2020-36869
HIGH
Nagios XI < 5.7.5 - Authenticated SQL Injection via SNMP Trap Interface Edit Page
Oct 30, 2025
CVSS 7.2
EPSS 0.01
CVE-2020-36868
HIGH
Nagios XI <5.7.3 - Privilege Escalation
Oct 30, 2025
CVSS 7.8
EPSS 0.00
CVE-2020-36867
HIGH
Nagios XI <5.7.3 - Command Injection
Oct 30, 2025
CVSS 8.8
EPSS 0.01
Products
nagios_xi 192
nagios 37
log_server 23
fusion 19
network_analyzer 7
nagios_core 5
XI 3
incident_manager 3
plugins 3
remote_plug_in_executor 3
Log Server 2
Nagios XI 2
favorites 2
nagios_cross_platform_agent 2
business_process_intelligence 1
nagios_network_analyzer 1
nagios_xi_docker_wizard 1
nagios_xi_switch_wizard 1
nagios_xi_watchguard_wizard 1
ndoutils 1
remote_plugin_executor 1
Quick Filters