nagios

301 tracked vulnerabilities.

CVE-2020-22427 HIGH
Nagios XI 5.6.11 - Authenticated Remote Code Execution
Feb 15, 2021
CVSS 7.2
EPSS 0.10
CVE-2020-25385 MEDIUM
Nagios Log Server < 2.1.7 - Stored Cross-Site Scripting via Snapshot Name Parameter
Jan 20, 2021
CVSS 6.1
EPSS 0.37
CVE-2020-35578 HIGH
Nagios XI < 5.8.0 - Authenticated OS Command Injection via Plugin Upload
Jan 13, 2021
CVSS 7.2
EPSS 0.85
CVE-2020-35269 HIGH
Nagios Core 4.2.4 - Cross-Site Request Forgery in Host Management Functions
Dec 23, 2020
CVSS 8.8
EPSS 0.01
CVE-2020-27991 MEDIUM
Nagios XI < 5.7.5 - Stored Cross-Site Scripting in Account Information Email Field
Nov 16, 2020
CVSS 5.4
EPSS 0.06
CVE-2020-27990 MEDIUM
Nagios XI < 5.7.5 - Cross-Site Scripting in Deployment Tool
Nov 16, 2020
CVSS 5.4
EPSS 0.06
CVE-2020-27989 MEDIUM
Nagios XI < 5.7.5 - Stored Cross-Site Scripting in Dashboard Tools
Nov 16, 2020
CVSS 5.4
EPSS 0.06
CVE-2020-27988 MEDIUM
Nagios XI < 5.7.5 - Stored Cross-Site Scripting in Manage Users Username Field
Nov 16, 2020
CVSS 5.4
EPSS 0.30
CVE-2020-28648 HIGH
Nagios XI < 5.7.5 - Authenticated Remote Code Execution via Auto-Discovery Input Validation
Nov 16, 2020
CVSS 8.8
EPSS 0.09
CVE-2020-5796 HIGH
Nagios XI <5.7.4 - Privilege Escalation
Nov 13, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-5792 HIGH
Nagios XI 5.7.3 - Command Injection
Oct 20, 2020
CVSS 7.2
EPSS 0.81
CVE-2020-5791 HIGH
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
Oct 20, 2020
CVSS 7.2
EPSS 0.88
CVE-2020-5790 MEDIUM
Nagios XI 5.7.3 - Cross-Site Request Forgery
Oct 20, 2020
CVSS 6.5
EPSS 0.03
CVE-2020-15903 CRITICAL
Nagios XI < 5.7.3 - Privilege Escalation via Editable Included Files
Sep 09, 2020
CVSS 9.8
EPSS 0.07
CVE-2020-16157 MEDIUM
Nagios Log Server < 2.1.7 - Stored Cross-Site Scripting via Email Users Notification Menu
Jul 30, 2020
CVSS 5.4
EPSS 0.07
CVE-2020-15902 MEDIUM
Nagios XI < 5.7.2 - Cross-Site Scripting via Graph Explorer Link URL
Jul 22, 2020
CVSS 6.1
EPSS 0.43
CVE-2020-15901 HIGH
Nagios XI <5.7.3 - Command Injection
Jul 22, 2020
CVSS 8.8
EPSS 0.39
CVE-2020-13977 MEDIUM
Nagios 4.4.5 - Privilege Escalation
Jun 09, 2020
CVSS 4.9
EPSS 0.02
CVE-2020-10821 MEDIUM
Nagios XI 5.6.11 - Stored Cross-Site Scripting via Theme Parameter
Mar 22, 2020
CVSS 4.8
EPSS 0.24
CVE-2020-10820 MEDIUM
Nagios XI 5.6.11 - Cross-Site Scripting via LDAP AD Integration Password Parameter
Mar 22, 2020
CVSS 4.8
EPSS 0.04
CVE-2020-10819 MEDIUM
Nagios XI 5.6.11 - Cross-Site Scripting via LDAP AD Integration Username Parameter
Mar 22, 2020
CVSS 4.8
EPSS 0.22
CVE-2020-6582 HIGH
Nagios NRPE 3.2.1 - Heap-Based Buffer Overflow via Incorrect Numeric Conversion
Mar 16, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-6581 HIGH
Nagios NRPE 3.2.1 - OS Command Injection via Insufficient Filtering
Mar 16, 2020
CVSS 7.3
EPSS 0.00
CVE-2020-6586 MEDIUM
Nagios Log Server 2.1.3 - Stored Cross-Site Scripting via User Profile Name Field
Mar 16, 2020
CVSS 5.4
EPSS 0.07
CVE-2020-6585 HIGH
Nagios Log Server 2.1.3 - Cross-Site Request Forgery
Mar 16, 2020
CVSS 8.8
EPSS 0.01