cbcvebase.

Nagios Xi vulnerabilities

76 known vulnerabilities affecting nagios/xi.

Total CVEs
76
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH25MEDIUM46

Vulnerabilities

Page 2 of 4
CVE-2012-10063P3CRITICALCVSS 9.8fixed in 2012R1.32025-10-30
CVE-2012-10063 [CRITICAL] CWE-89 CVE-2012-10063: Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Config Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to configuration data stored in the application database. Successful exploitation cou
nvd
CVE-2024-14008P3HIGHCVSS 7.2fixed in 2024R1.3.22025-10-30
CVE-2024-14008 [HIGH] CWE-78 CVE-2024-14008: Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated administrator to inject shell metacharacters that are incorporated into backend command invocations. Successful exploitation enables arbitrary command execution
nvd
CVE-2024-13997P3HIGHCVSS 7.2fixed in 2024R1.1.32025-11-03
CVE-2024-13997 [HIGH] CWE-269 CVE-2024-13997: Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an auth Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host. By abusing the migration workflow, an admin-level attacker could execute actions outside the intended security scope of the applicatio
nvd
CVE-2024-14009P3HIGHCVSS 7.2fixed in 2024R1.0.12025-10-30
CVE-2024-14009 [HIGH] CWE-269 CVE-2024-14009: Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Pr Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. Due to improper access controls and unsafe handling of exported/imported profile data and operations, an authenticated administrator could exploit this
nvd
CVE-2020-36869P3HIGHCVSS 7.2fixed in 5.7.52025-10-30
CVE-2020-36869 [HIGH] CWE-89 CVE-2020-36869: Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface e Nagios XI versions prior to 5.7.5 contain a SQL injection vulnerability in the SNMP Trap Interface edit page. Exploitation requires an account with administrative privileges to access the affected interface. A user with administrative access could supply crafted input that is not properly sanitized, allowing SQL injection that may lead to unauthorized
nvd
CVE-2020-36868P3HIGHCVSS 7.8fixed in 5.7.32025-10-30
CVE-2020-36868 [HIGH] CWE-73 CVE-2020-36868: Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh Nagios XI versions prior to 5.7.3 contain a privilege escalation vulnerability in the getprofile.sh helper script. The script performed profile retrieval and initialization routines using insecure file/command handling and insufficient validation of attacker-controlled inputs, and in some deployments executed with elevated privileges. A local attacker w
nvd
CVE-2018-25123P3HIGHCVSS 7.8fixed in 5.5.72025-10-30
CVE-2018-25123 [HIGH] CWE-250 CVE-2018-25123: Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing Nagios XI versions prior to 5.5.7 contain a privilege escalation vulnerability in the MRTG graphing component. MRTG-related processes/scripts executed with excessive privileges, allowing a local attacker with limited system access to abuse file/command execution paths or writable resources to gain elevated privileges.
nvd
CVE-2025-34287P3HIGHCVSS 7.8fixed in 2024R22025-10-30
CVE-2025-34287 [HIGH] CWE-732 CVE-2025-34287: Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next
nvd
CVE-2021-47700P3HIGHCVSS 7.8fixed in 5.8.72025-10-30
CVE-2021-47700 [HIGH] CWE-250 CVE-2021-47700: Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly perm Nagios XI versions prior to 5.8.7 used a temporary directory for Highcharts exports with overly permissive ownership/permissions under the Apache user. Local or co-hosted processes could read/overwrite export artifacts or manipulate paths, risking disclosure or tampering and potential code execution depending on deployment.
nvd
CVE-2025-34283P3MEDIUMCVSS 6.5fixed in 2024R1.4.22025-10-30
CVE-2025-34283 [MEDIUM] CWE-497 CVE-2025-34283: Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API ac Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
nvd
CVE-2013-10072P3MEDIUMCVSS 6.5fixed in 2012R1.62025-10-30
CVE-2013-10072 [MEDIUM] CWE-862 CVE-2013-10072: Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionali Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing unintended access to discovery operations.
nvd
CVE-2011-10035P3HIGHCVSS 7.0fixed in 2011R1.92025-10-30
CVE-2011-10035 [HIGH] CWE-367 CVE-2011-10035: Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts tha Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the
nvd
CVE-2024-14006P4MEDIUMCVSS 6.1fixed in 2024R1.2.22025-10-30
CVE-2024-14006 [MEDIUM] CWE-346 CVE-2024-14006: Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The applicatio Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to poison generated links or responses, which may facilitate phishing of cr
nvd
CVE-2020-36862P4MEDIUMCVSS 6.1fixed in 5.6.112025-10-30
CVE-2020-36862 [MEDIUM] CWE-79 CVE-2020-36862: Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local e Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content due to insufficient output encoding (XSS), and (2) cause the server to fetch attacker-specified URLs (SSRF), potentially accessing internal network resources.
nvd
CVE-2021-47694P4MEDIUMCVSS 6.1fixed in 5.8.62025-10-30
CVE-2021-47694 [MEDIUM] CWE-79 CVE-2021-47694: The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via the Test Command functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-14002P4MEDIUMCVSS 5.5fixed in 2024R1.1.42025-10-30
CVE-2024-14002 [MEDIUM] CWE-98 CVE-2024-14002: Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its Na Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values that cause the server to include local files, potentially exposing sensitive information from the underlying host.
nvd
CVE-2024-13993P4MEDIUMCVSS 6.1fixed in 2024R1.1.22025-10-30
CVE-2024-13993 [MEDIUM] CWE-79 CVE-2024-13993: Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) vi Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. Insufficient validation or escaping of user-supplied input reflected by the login page can allow an attacker to craft a malicious link that, when visited by a victim, executes arbitrary JavaScript
nvd
CVE-2013-10071P4MEDIUMCVSS 6.1fixed in 2012R1.62025-10-30
CVE-2013-10071 [MEDIUM] CWE-79 CVE-2013-10071: Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2011-10037P4MEDIUMCVSS 5.4fixed in 2011R1.92025-10-30
CVE-2011-10037 [MEDIUM] CWE-79 CVE-2011-10037: Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling o Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the handling of xiwindow variables used to build permalinks in the web interface. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
nvd
CVE-2024-13992P4MEDIUMCVSS 5.4fixed in 2024R1.12025-10-31
CVE-2024-13992 [MEDIUM] CWE-79 CVE-2024-13992: Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user vis Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to properly validate or escape user-supplied input, allowing an attacker to craft a malicious link that, when visited by a
nvd
Nagios Xi vulnerabilities | cvebase