cbcvebase.

Nagios Xi vulnerabilities

76 known vulnerabilities affecting nagios/xi.

Total CVEs
76
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH25MEDIUM46

Vulnerabilities

Page 1 of 4
CVE-2024-14003P2CRITICALCVSS 9.8fixed in 2024R1.22025-10-30
CVE-2024-14003 [CRITICAL] CWE-78 CVE-2024-14003: Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach command execution paths, enabling attackers to execute arbitrary commands on the underlying host in the context of
nvd
CVE-2013-10073P2HIGHCVSS 8.8fixed in 2012R1.62025-10-30
CVE-2013-10073 [HIGH] CWE-78 CVE-2013-10073: Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Dis Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to discovery functionality to execute arbitrary commands with the privileges of the application service.
nvd
CVE-2024-13999P2CRITICALCVSS 9.8fixed in 2024R1.1.32025-10-30
CVE-2024-13999 [CRITICAL] CWE-497 CVE-2024-13999: Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Di Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
nvd
CVE-2025-34284P2HIGHCVSS 8.8fixed in 2024R22025-10-30
CVE-2025-34284 [HIGH] CWE-78 CVE-2025-34284: Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. In Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation enables arbitrary command execution with the privileges
nvd
CVE-2018-25122P2HIGHCVSS 8.8fixed in 5.4.132025-10-30
CVE-2018-25122 [HIGH] CWE-78 CVE-2018-25122: Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Do Nagios XI versions prior to 5.4.13 contain a remote code execution vulnerability in the Component Download page. The download/import handler used unsafe command construction with attacker-controlled input and lacked sufficient validation and output encoding, allowing an authenticated user to inject commands or otherwise execute arbitrary code with the
nvd
CVE-2024-14005P2HIGHCVSS 8.8fixed in 2024R1.22025-10-30
CVE-2024-14005 [HIGH] CWE-78 CVE-2024-14005: Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation enables arbitrary command execution with th
nvd
CVE-2023-7317P2HIGHCVSS 8.8fixed in 2024R12025-10-30
CVE-2023-7317 [HIGH] CWE-862 CVE-2023-7317: Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Te Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient authorization, potentially allowing unauthorized command execution or disclosure of sensitive information.
nvd
CVE-2020-36856P2HIGHCVSS 8.8fixed in 5.6.142025-10-30
CVE-2020-36856 [HIGH] CWE-78 CVE-2020-36856: Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability i Nagios XI versions prior to 5.6.14 contain an authenticated remote command execution vulnerability in the CCM command_test.php script. Insufficient validation of the `address` parameter allows an authenticated user with access to the Core Config Manager to inject shell metacharacters that are incorporated into backend command invocations. Successful ex
nvd
CVE-2020-36863P2HIGHCVSS 8.8fixed in 5.7.22025-10-30
CVE-2020-36863 [HIGH] CWE-434 CVE-2020-36863: Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and e Nagios XI versions prior to 5.7.2 allow PHP files to be uploaded to the Audio Import directory and executed from that location. The upload handler did not properly restrict file types or enforce storage outside of the webroot, and the web server permitted execution within the upload directory. An authenticated attacker with access to the audio import
nvd
CVE-2024-13994P2CRITICALCVSS 9.8fixed in 2024R1.1.22025-10-30
CVE-2024-13994 [CRITICAL] CWE-862 CVE-2024-13994: Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insec Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios
nvd
CVE-2020-36867P2HIGHCVSS 8.8fixed in 5.7.32025-10-30
CVE-2020-36867 [HIGH] CWE-78 CVE-2020-36867: Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF downlo Nagios XI versions prior to 5.7.3 contain a command injection vulnerability in the report PDF download/export functionality. User-supplied values used in the PDF generation pipeline or the wrapper that invokes offline/pdf helper utilities were insufficiently validated or improperly escaped, allowing an authenticated attacker who can trigger PDF exports
nvd
CVE-2024-13995P2HIGHCVSS 8.8fixed in 2024R1.1.32025-10-30
CVE-2024-13995 [HIGH] CWE-497 CVE-2024-13995: Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Exposure of API keys or password hashes could lead to account compromise, abuse of API privileges, or offline cracking at
nvd
CVE-2016-15050P3HIGHCVSS 8.8fixed in 5.2.42025-10-30
CVE-2016-15050 [HIGH] CWE-89 CVE-2016-15050: Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search f Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-supplied search parameters were incorporated into SQL statements without adequate parameterization or sanitation, allowing an authenticated user to manipulate database queries. Successful exploitation could disclose or modify notificat
nvd
CVE-2024-13996P3CRITICALCVSS 9.8fixed in 2024R1.1.32025-10-30
CVE-2024-13996 [CRITICAL] CWE-613 CVE-2024-13996: Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access
nvd
CVE-2020-36859P3HIGHCVSS 8.8fixed in 5.7.42025-10-30
CVE-2020-36859 [HIGH] CWE-89 CVE-2020-36859: The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains mu The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple SQL injection vulnerabilities in the object edit pages. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing authenticated users to inject SQL fragments. Successful exploitation could lea
nvd
CVE-2025-34286P3HIGHCVSS 7.2fixed in 2026R12025-10-30
CVE-2025-34286 [HIGH] CWE-78 CVE-2025-34286: Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines allows an authenticated administrator to inject shell metacharacters that are executed on the server. Successful exploitation results in ar
nvd
CVE-2024-14004P3HIGHCVSS 8.8fixed in 2024R1.22025-10-30
CVE-2024-14004 [HIGH] CWE-269 CVE-2024-14004: Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validated configuration settings to obtain elevated privileges on the Nagios XI system.
nvd
CVE-2025-34134P3HIGHCVSS 7.2fixed in 2024R1.4.22025-10-30
CVE-2025-34134 [HIGH] CWE-78 CVE-2025-34134: Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled BPI configuration parameters (notably bpi_logfile and bpi_configfile) allow an authenticated administrative user to cause the product to create or
nvd
CVE-2021-47693P3HIGHCVSS 8.8fixed in 5.8.52025-10-30
CVE-2021-47693 [HIGH] CWE-89 CVE-2021-47693: The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.3 / Nagios XI 5.8.5 contains a SQL injection vulnerability in the search text handling. Unsanitized user-supplied input was incorporated into SQL queries used by configuration object editors, allowing authenticated users to inject SQL fragments. Successful exploitation could lead to un
nvd
CVE-2020-36857P3HIGHCVSS 7.2fixed in 5.6.142025-10-30
CVE-2020-36857 [HIGH] CWE-89 CVE-2020-36857: Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the Nagios XI versions prior to 5.6.14 contain a post-authentication SQL injection vulnerability in the SNMP Trap Interface page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized, allowing SQL injection that may lead t
nvd
Nagios Xi vulnerabilities | cvebase