Vulnerabilities > Nagios > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-07 CVE-2024-43199 Incorrect Permission Assignment for Critical Resource vulnerability in Nagios Ndoutils
Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.
local
low complexity
nagios CWE-732
7.8
2023-09-19 CVE-2023-40933 SQL Injection vulnerability in Nagios XI
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
network
low complexity
nagios CWE-89
8.8
2023-09-19 CVE-2023-40934 SQL Injection vulnerability in Nagios XI
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
network
low complexity
nagios CWE-89
7.2
2021-10-26 CVE-2021-40343 Incorrect Permission Assignment for Critical Resource vulnerability in Nagios XI 5.8.5
An issue was discovered in Nagios XI 5.8.5.
local
low complexity
nagios CWE-732
7.8
2021-10-26 CVE-2021-40344 Unrestricted Upload of File with Dangerous Type vulnerability in Nagios XI 5.8.5
An issue was discovered in Nagios XI 5.8.5.
network
low complexity
nagios CWE-434
7.2
2021-10-26 CVE-2021-40345 Command Injection vulnerability in Nagios XI 5.8.5
An issue was discovered in Nagios XI 5.8.5.
network
low complexity
nagios CWE-77
7.2
2021-10-14 CVE-2021-33177 SQL Injection vulnerability in Nagios XI
The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection.
network
low complexity
nagios CWE-89
8.8
2021-08-13 CVE-2021-37343 Path Traversal vulnerability in Nagios XI
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
network
low complexity
nagios CWE-22
8.8
2021-08-13 CVE-2021-37345 Improper Privilege Management vulnerability in Nagios XI
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
local
low complexity
nagios CWE-269
7.8
2021-08-13 CVE-2021-37347 Path Traversal vulnerability in Nagios XI
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
local
low complexity
nagios CWE-22
7.8