Show filters
185 Total Results
Displaying 71-80 of 185
Sort by:
Attacker Value
Unknown

CVE-2021-26023

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
Attacker Value
Unknown

CVE-2021-26024

Disclosure Date: February 03, 2021 (last updated February 22, 2025)
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
Attacker Value
Unknown

CVE-2021-3193

Disclosure Date: January 26, 2021 (last updated November 28, 2024)
Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.
Attacker Value
Unknown

CVE-2020-25385

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
Attacker Value
Unknown

CVE-2020-35578

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-system commands.
Attacker Value
Unknown

CVE-2020-35269

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
Attacker Value
Unknown

CVE-2020-27991

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Nagios XI before 5.7.5 is vulnerable to XSS in Account Information (Email field).
Attacker Value
Unknown

CVE-2020-27990

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Nagios XI before 5.7.5 is vulnerable to XSS in the Deployment tool (add agent).
Attacker Value
Unknown

CVE-2020-27989

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Nagios XI before 5.7.5 is vulnerable to XSS in Dashboard Tools (Edit Dashboard).
Attacker Value
Unknown

CVE-2020-27988

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).