VendorsNagiosnagios_xiall versions
Vulnerabilities

Nagios Nagios Xi

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

194CVEs
CVE-2018-8735
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.
Published 2018-04-18 · Modified
9.02 PoCEPSS 0.636
CVE-2021-25297
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.
Published 2021-02-15 · Analyzed
9.0KEVEPSS 0.567
CVE-2018-8736
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.
Published 2018-04-18 · Modified
9.02 PoCEPSS 0.463
CVE-2021-40345
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
Published 2021-10-26 · Modified
9.0EPSS 0.227
CVE-2019-20197
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
Published 2019-12-31 · Modified
9.0EPSS 0.224
CVE-2021-3273
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.
Published 2021-02-25 · Modified
9.0EPSS 0.072
CVE-2020-28648
Improper input validation in the Auto-Discovery component of Nagios XI before 5.7.5 allows an authenticated attacker to execute remote code.
Published 2020-11-16 · Modified
9.0EPSS 0.062
CVE-2020-28906
Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.
Published 2021-05-24 · Modified
9.0EPSS 0.047
CVE-2026-2043
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability
Published 2026-02-20 · Analyzed
8.8EPSS 0.737
CVE-2026-2041
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability
Published 2026-02-20 · Analyzed
8.8EPSS 0.737
CVE-2019-9164
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
Published 2019-03-28 · Modified
8.8EPSS 0.460
CVE-2018-15711
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then use the new API key to execute API calls at elevated privileges.
Published 2018-11-14 · Modified
8.8EPSS 0.360
CVE-2025-34227
Nagios XI < 2026R1 Configuration Wizard Authenticated Command Injection
Published 2025-09-25 · Analyzed
8.8EPSS 0.243
CVE-2021-37343
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
Published 2021-08-13 · Modified
8.8EPSS 0.238
CVE-2020-15901
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
Published 2020-07-22 · Modified
8.8EPSS 0.219
CVE-2018-15709
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
Published 2018-11-14 · Modified
8.8EPSS 0.210
CVE-2020-24899
Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query.
Published 2021-02-15 · Modified
8.8EPSS 0.166
CVE-2021-33177
The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.
Published 2021-10-14 · Modified
8.8EPSS 0.101
CVE-2026-2042
Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability
Published 2026-02-20 · Analyzed
8.8EPSS 0.056
CVE-2023-40933
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
Published 2023-09-19 · Modified
8.8EPSS 0.035
CVE-2013-10073
Nagios XI < 2012R1.6 Auto-Discovery Shell Command Injection
Published 2025-10-30 · Analyzed
8.8EPSS 0.035
CVE-2020-36867
Nagios XI < 5.7.3 Command Injection in Report PDF Download
Published 2025-10-30 · Analyzed
8.8EPSS 0.026
CVE-2024-13986
Nagios XI < 2024R1.3.2 Authenticated Arbitrary File Upload Path Traversal RCE
Published 2025-08-28 · Modified
8.8EPSS 0.017
CVE-2018-25122
Nagios XI < 5.4.13 Component Download Page RCE
Published 2025-10-30 · Analyzed
8.8EPSS 0.016
CVE-2024-33775
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
Published 2024-05-01 · Modified
8.8EPSS 0.014
CVE-2020-36863
Nagios XI < 5.7.2 Unrestricted File Upload via Audio Import Directory
Published 2025-10-30 · Analyzed
8.8EPSS 0.013
CVE-2024-13995
Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure
Published 2025-10-30 · Analyzed
8.8EPSS 0.012
CVE-2025-67255
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.
Published 2025-12-29 · Analyzed
8.8EPSS 0.011
CVE-2021-47693
Nagios XI < 5.8.5 Core Config Manager (CCM) SQL Injection via Improper Escaping in Search Text
Published 2025-10-30 · Analyzed
8.8EPSS 0.011
CVE-2024-14004
Nagios XI < 2024R1.2 Privilege Escalation via NagVis Configuration (nagvis.conf)
Published 2025-10-30 · Analyzed
8.8EPSS 0.010
CVE-2016-15050
Nagios XI < 5.2.4 SQL Injection in Notification Search
Published 2025-10-30 · Analyzed
8.8EPSS 0.010
CVE-2020-36859
Nagios XI < 5.7.4 Core Config Manager (CCM) SQL Injection via Object Edit Pages
Published 2025-10-30 · Analyzed
8.8EPSS 0.009
CVE-2024-14006
Nagios XI < 2024R1.2.2 Host Header Injection
Published 2025-10-30 · Analyzed
8.8EPSS 0.004
CVE-2020-36869
Nagios XI < 5.7.5 SQL injection via SNMP Trap Interface Edit Page
Published 2025-10-30 · Analyzed
8.7EPSS 0.018
CVE-2020-36857
Nagios XI < 5.6.14 Authenticated SQL Injection via SNMP Trap Interface Page
Published 2025-10-30 · Analyzed
8.6EPSS 0.021
CVE-2025-34288
Nagios XI Privilege Escalation via Writable PHP Include Executed with Sudo
Published 2025-12-16 · Analyzed
8.6EPSS 0.019
CVE-2021-47700
Nagios XI < 5.8.7 Insecure Permissions on Highcharts Temporary Directory
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2018-25123
Nagios XI < 5.5.7 Privilege Escalation via MRTG Graphing Component
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2020-36868
Nagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh Script
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2025-34287
Nagios XI < 2024R2 Privilege Escalation via process_perfdata.pl
Published 2025-10-30 · Analyzed
8.4EPSS 0.003
← Prev2 / 5Next →