Vulnerabilities > Nagios > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-07 | CVE-2024-43199 | Incorrect Permission Assignment for Critical Resource vulnerability in Nagios Ndoutils Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user. | 7.8 |
2023-09-19 | CVE-2023-40933 | SQL Injection vulnerability in Nagios XI A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function. | 8.8 |
2023-09-19 | CVE-2023-40934 | SQL Injection vulnerability in Nagios XI A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. | 7.2 |
2021-10-26 | CVE-2021-40343 | Incorrect Permission Assignment for Critical Resource vulnerability in Nagios XI 5.8.5 An issue was discovered in Nagios XI 5.8.5. | 7.8 |
2021-10-26 | CVE-2021-40344 | Unrestricted Upload of File with Dangerous Type vulnerability in Nagios XI 5.8.5 An issue was discovered in Nagios XI 5.8.5. | 7.2 |
2021-10-26 | CVE-2021-40345 | Command Injection vulnerability in Nagios XI 5.8.5 An issue was discovered in Nagios XI 5.8.5. | 7.2 |
2021-10-14 | CVE-2021-33177 | SQL Injection vulnerability in Nagios XI The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. | 8.8 |
2021-08-13 | CVE-2021-37343 | Path Traversal vulnerability in Nagios XI A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios. | 8.8 |
2021-08-13 | CVE-2021-37345 | Improper Privilege Management vulnerability in Nagios XI Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions. | 7.8 |
2021-08-13 | CVE-2021-37347 | Path Traversal vulnerability in Nagios XI Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument. | 7.8 |