Total
194 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-48084 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 9.8 CRITICAL |
| Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool. | |||||
| CVE-2023-48082 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 9.1 CRITICAL |
| Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate. | |||||
| CVE-2022-50588 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
| CVE-2022-50587 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
| CVE-2022-50586 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
| CVE-2022-50585 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.7 / Nagios XI 5.8.9 contains a cross-site scripting (XSS) vulnerability via the Audit Log page search input. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
| CVE-2022-50584 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the search and deletion interfaces. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
| CVE-2022-38254 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 6.1 MEDIUM |
| Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5. | |||||
| CVE-2022-38251 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 4.8 MEDIUM |
| Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel. | |||||
| CVE-2022-38250 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 9.8 CRITICAL |
| Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | |||||
| CVE-2022-38249 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 6.1 MEDIUM |
| Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4. | |||||
| CVE-2022-38248 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 6.1 MEDIUM |
| Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php. | |||||
| CVE-2022-38247 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 4.8 MEDIUM |
| Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel. | |||||
| CVE-2022-29272 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | 5.8 MEDIUM | 6.1 MEDIUM |
| In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing. | |||||
| CVE-2022-29271 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | 4.0 MEDIUM | 6.5 MEDIUM |
| In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks. | |||||
| CVE-2022-29270 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | 4.0 MEDIUM | 4.3 MEDIUM |
| In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address. | |||||
| CVE-2022-29269 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | 4.0 MEDIUM | 6.5 MEDIUM |
| In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address. | |||||
| CVE-2021-47700 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 7.8 HIGH |
| Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment. | |||||
| CVE-2021-47699 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
| CVE-2021-47698 | 1 Nagios | 1 Nagios Xi | 2026-06-17 | N/A | 5.4 MEDIUM |
| Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser. | |||||
