Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nagios nagios xi vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2024-33775
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote malicious user to escalate privileges via a crafted Dashlet.
1 Github repository
NA
CVE-2024-24401
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote malicious user to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
NA
CVE-2024-24402
An issue in Nagios XI 2024R1.01 allows a remote malicious user to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
5.4
CVSSv3
CVE-2023-51072
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows a...
Nagios Nagios Xi
Nagios Nagios Xi 2024
9.8
CVSSv3
CVE-2023-48084
Nagios XI before version 5.11.3 exists to contain a SQL injection vulnerability via the bulk modification tool.
Nagios Nagios Xi
2 Github repositories
9.8
CVSSv3
CVE-2023-48085
Nagios XI before version 5.11.3 exists to contain a remote code execution (RCE) vulnerability via the component command_test.php.
Nagios Nagios Xi
6.5
CVSSv3
CVE-2023-40931
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated malicious users to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
Nagios Nagios Xi
1 Github repository
7.2
CVSSv3
CVE-2023-40934
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
Nagios Nagios Xi
8.8
CVSSv3
CVE-2023-40933
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
Nagios Nagios Xi
1 Github repository
5.4
CVSSv3
CVE-2023-40932
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login...
Nagios Nagios Xi
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »