Vulnerabilities > Nagios > Nagios XI

DATE CVE VULNERABILITY TITLE RISK
2021-10-26 CVE-2021-40344 Unrestricted Upload of File with Dangerous Type vulnerability in Nagios XI 5.8.5
An issue was discovered in Nagios XI 5.8.5.
network
low complexity
nagios CWE-434
7.2
2021-10-26 CVE-2021-40345 Command Injection vulnerability in Nagios XI 5.8.5
An issue was discovered in Nagios XI 5.8.5.
network
low complexity
nagios CWE-77
7.2
2021-10-14 CVE-2021-33177 SQL Injection vulnerability in Nagios XI
The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection.
network
low complexity
nagios CWE-89
8.8
2021-10-14 CVE-2021-33179 Cross-site Scripting vulnerability in Nagios XI
The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scripting.
network
low complexity
nagios CWE-79
6.1
2021-10-05 CVE-2021-37223 Server-Side Request Forgery (SSRF) vulnerability in Nagios XI
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php.
network
low complexity
nagios CWE-918
6.5
2021-09-28 CVE-2021-36363 Incorrect Default Permissions vulnerability in Nagios XI
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.
network
low complexity
nagios CWE-276
critical
9.8
2021-09-28 CVE-2021-36364 Unspecified vulnerability in Nagios XI
Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.
network
low complexity
nagios
critical
9.8
2021-09-28 CVE-2021-36365 Incorrect Default Permissions vulnerability in Nagios XI
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.
network
low complexity
nagios CWE-276
critical
9.8
2021-09-28 CVE-2021-36366 Unspecified vulnerability in Nagios XI
Nagios XI before 5.8.5 incorrectly allows manage_services.sh wildcards.
network
low complexity
nagios
critical
9.8
2021-09-15 CVE-2021-38156 Cross-site Scripting vulnerability in Nagios XI
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
network
low complexity
nagios CWE-79
5.4