nagios

301 tracked vulnerabilities.

CVE-2021-37351 MEDIUM
Nagios XI < 5.8.5 - Unauthenticated Access to Guarded Pages via Crafted HTTP Request
Aug 13, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-37350 CRITICAL
Nagios XI < 5.8.5 - SQL Injection via Bulk Modifications Tool
Aug 13, 2021
CVSS 9.8
EPSS 0.41
CVE-2021-37349 HIGH
Nagios XI < 5.8.5 - Local Privilege Escalation via cleaner.php Database Input
Aug 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-37348 HIGH
Nagios XI < 5.8.5 - Local File Inclusion via index.php
Aug 13, 2021
CVSS 7.5
EPSS 0.12
CVE-2021-37347 HIGH
Nagios XI < 5.8.5 - Local Privilege Escalation via getprofile.sh Directory Argument
Aug 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-37346 CRITICAL
Nagios XI WatchGuard Wizard < 1.4.8 - Remote Code Execution via OS Command Injection
Aug 13, 2021
CVSS 9.8
EPSS 0.55
CVE-2021-37345 HIGH
Nagios XI < 5.8.5 - Local Privilege Escalation via xi-sys.cfg Import
Aug 13, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-37344 CRITICAL
Nagios XI Switch Wizard < 2.5.7 - Remote Code Execution via OS Command Injection
Aug 13, 2021
CVSS 9.8
EPSS 0.57
CVE-2021-37343 HIGH
Nagios XI Autodiscovery Webshell Upload
Aug 13, 2021
CVSS 8.8
EPSS 0.83
CVE-2021-35479 MEDIUM
Nagios Log Server < 2.1.9 - Stored Cross-Site Scripting via Custom Column View
Jul 30, 2021
CVSS 5.4
EPSS 0.48
CVE-2021-35478 MEDIUM
Nagios Log Server < 2.1.9 - Reflected Cross-Site Scripting via Alert History and Audit Log Dropdown
Jul 30, 2021
CVSS 5.4
EPSS 0.49
CVE-2021-3277 HIGH
Nagios XI < 5.7.5 - Authenticated Remote Code Execution via Custom-Includes Rename Functionality
Jun 07, 2021
CVSS 7.2
EPSS 0.35
CVE-2021-28925 CRITICAL
Nagios Network Analyzer < 2.4.3 - SQL Injection via o[col] Parameter
Apr 08, 2021
CVSS 9.8
EPSS 0.48
CVE-2021-28924 MEDIUM
Nagios Network Analyzer < 2.4.3 - Authenticated Cross-Site Scripting via Groups Queries Page
Apr 08, 2021
CVSS 6.1
EPSS 0.52
CVE-2021-3273 HIGH
Nagios XI < 5.7 - Authenticated Code Injection in graphtemplates.php
Feb 25, 2021
CVSS 7.2
EPSS 0.26
CVE-2021-25299 MEDIUM NUCLEI
Nagios XI 5.7.5 - Stored Cross-Site Scripting in SSH Terminal Admin Page
Feb 15, 2021
CVSS 6.1
EPSS 0.85
CVE-2021-25298 HIGH KEVNUCLEI
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
Feb 15, 2021
CVSS 8.8
EPSS 0.75
CVE-2021-25297 HIGH KEVNUCLEI
Nagios XI xi-5.7.5 - Command Injection
Feb 15, 2021
CVSS 8.8
EPSS 0.82
CVE-2021-25296 HIGH KEVNUCLEI
Nagios XI xi-5.7.5 - Command Injection
Feb 15, 2021
CVSS 8.8
EPSS 0.93
CVE-2021-26024 MEDIUM
Nagios XI Favorites < 1.0.2 - Insecure Direct Object Reference
Feb 03, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-26023 MEDIUM
Nagios Favorites < 1.0.2 - Cross-Site Scripting
Feb 03, 2021
CVSS 6.1
EPSS 0.38
CVE-2021-3193 CRITICAL
Nagios XI < 5.7.0 - Unauthenticated Remote Code Execution via Docker Config Wizard
Jan 26, 2021
CVSS 9.8
EPSS 0.25
CVE-2020-36869 HIGH
Nagios XI < 5.7.5 - Authenticated SQL Injection via SNMP Trap Interface Edit Page
Oct 30, 2025
CVSS 7.2
EPSS 0.01
CVE-2020-36868 HIGH
Nagios XI <5.7.3 - Privilege Escalation
Oct 30, 2025
CVSS 7.8
EPSS 0.00
CVE-2020-36867 HIGH
Nagios XI <5.7.3 - Command Injection
Oct 30, 2025
CVSS 8.8
EPSS 0.01