Vulnerabilities > Nagios

DATE CVE VULNERABILITY TITLE RISK
2021-02-25 CVE-2021-3273 Code Injection vulnerability in Nagios XI
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component.
network
low complexity
nagios CWE-94
7.2
2021-02-15 CVE-2020-24899 OS Command Injection vulnerability in Nagios XI 5.7.2
Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability.
network
low complexity
nagios CWE-78
8.8
2021-02-15 CVE-2020-22427 Unspecified vulnerability in Nagios XI 5.6.11
NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability.
network
low complexity
nagios
7.2
2021-02-15 CVE-2021-25299 Cross-site Scripting vulnerability in Nagios XI 5.7.5
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS).
network
low complexity
nagios CWE-79
6.1
2021-02-15 CVE-2021-25298 Unspecified vulnerability in Nagios XI 5.7.5
Nagios XI version xi-5.7.5 is affected by OS command injection.
network
low complexity
nagios
8.8
2021-02-15 CVE-2021-25297 Unspecified vulnerability in Nagios XI 5.7.5
Nagios XI version xi-5.7.5 is affected by OS command injection.
network
low complexity
nagios
8.8
2021-02-15 CVE-2021-25296 Unspecified vulnerability in Nagios XI 5.7.5
Nagios XI version xi-5.7.5 is affected by OS command injection.
network
low complexity
nagios
8.8
2021-02-03 CVE-2021-26024 Authorization Bypass Through User-Controlled Key vulnerability in Nagios Favorites
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
network
low complexity
nagios CWE-639
5.3
2021-02-03 CVE-2021-26023 Cross-site Scripting vulnerability in Nagios Favorites
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
network
low complexity
nagios CWE-79
6.1
2021-01-26 CVE-2021-3193 Unspecified vulnerability in Nagios XI
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
network
low complexity
nagios
critical
9.8