VendorsNagiosnagios_xiany version
Vulnerabilities

Nagios Nagios Xi any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

148CVEs
CVE-2020-28906
Incorrect File Permissions in Nagios XI 5.7.5 and earlier and Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to root. Low-privileged users are able to modify files that are included (aka sourced) by scripts executed by root.
Published 2021-05-24 · Modified
9.0EPSS 0.047
CVE-2019-9164
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
Published 2019-03-28 · Modified
8.8EPSS 0.460
CVE-2025-34227
Nagios XI < 2026R1 Configuration Wizard Authenticated Command Injection
Published 2025-09-25 · Analyzed
8.8EPSS 0.243
CVE-2021-37343
A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post authenticated RCE under security context of the user running Nagios.
Published 2021-08-13 · Modified
8.8EPSS 0.238
CVE-2020-15901
In Nagios XI before 5.7.3, ajaxhelper.php allows remote authenticated attackers to execute arbitrary commands via cmdsubsys.
Published 2020-07-22 · Modified
8.8EPSS 0.219
CVE-2021-33177
The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulnerable system, but once authenticated they would be able to execute arbitrary sql queries.
Published 2021-10-14 · Modified
8.8EPSS 0.101
CVE-2023-40933
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
Published 2023-09-19 · Modified
8.8EPSS 0.035
CVE-2013-10073
Nagios XI < 2012R1.6 Auto-Discovery Shell Command Injection
Published 2025-10-30 · Analyzed
8.8EPSS 0.035
CVE-2020-36867
Nagios XI < 5.7.3 Command Injection in Report PDF Download
Published 2025-10-30 · Analyzed
8.8EPSS 0.026
CVE-2024-13986
Nagios XI < 2024R1.3.2 Authenticated Arbitrary File Upload Path Traversal RCE
Published 2025-08-28 · Modified
8.8EPSS 0.017
CVE-2018-25122
Nagios XI < 5.4.13 Component Download Page RCE
Published 2025-10-30 · Analyzed
8.8EPSS 0.016
CVE-2020-36863
Nagios XI < 5.7.2 Unrestricted File Upload via Audio Import Directory
Published 2025-10-30 · Analyzed
8.8EPSS 0.013
CVE-2024-13995
Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure
Published 2025-10-30 · Analyzed
8.8EPSS 0.012
CVE-2021-47693
Nagios XI < 5.8.5 Core Config Manager (CCM) SQL Injection via Improper Escaping in Search Text
Published 2025-10-30 · Analyzed
8.8EPSS 0.011
CVE-2024-14004
Nagios XI < 2024R1.2 Privilege Escalation via NagVis Configuration (nagvis.conf)
Published 2025-10-30 · Analyzed
8.8EPSS 0.010
CVE-2016-15050
Nagios XI < 5.2.4 SQL Injection in Notification Search
Published 2025-10-30 · Analyzed
8.8EPSS 0.010
CVE-2020-36859
Nagios XI < 5.7.4 Core Config Manager (CCM) SQL Injection via Object Edit Pages
Published 2025-10-30 · Analyzed
8.8EPSS 0.009
CVE-2024-14006
Nagios XI < 2024R1.2.2 Host Header Injection
Published 2025-10-30 · Analyzed
8.8EPSS 0.004
CVE-2020-36869
Nagios XI < 5.7.5 SQL injection via SNMP Trap Interface Edit Page
Published 2025-10-30 · Analyzed
8.7EPSS 0.018
CVE-2020-36857
Nagios XI < 5.6.14 Authenticated SQL Injection via SNMP Trap Interface Page
Published 2025-10-30 · Analyzed
8.6EPSS 0.021
CVE-2025-34288
Nagios XI Privilege Escalation via Writable PHP Include Executed with Sudo
Published 2025-12-16 · Analyzed
8.6EPSS 0.019
CVE-2021-47700
Nagios XI < 5.8.7 Insecure Permissions on Highcharts Temporary Directory
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2018-25123
Nagios XI < 5.5.7 Privilege Escalation via MRTG Graphing Component
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2020-36868
Nagios XI < 5.7.3 Privilege escalation via Insecure getprofile.sh Script
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2025-34287
Nagios XI < 2024R2 Privilege Escalation via process_perfdata.pl
Published 2025-10-30 · Analyzed
8.4EPSS 0.003
CVE-2019-9166
Privilege escalation in Nagios XI before 5.5.11 allows local attackers to elevate privileges to root via write access to config.inc.php and import_xiconfig.php.
Published 2019-03-28 · Modified
7.8EPSS 0.012
CVE-2021-37347
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
Published 2021-08-13 · Modified
7.8EPSS 0.008
CVE-2021-37349
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input read from the database.
Published 2021-08-13 · Modified
7.8EPSS 0.007
CVE-2021-37345
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
Published 2021-08-13 · Modified
7.8EPSS 0.006
CVE-2013-6875
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.
Published 2013-11-26 · Modified
7.51 PoCEPSS 0.032
CVE-2021-37348
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index.php.
Published 2021-08-13 · Modified
7.5EPSS 0.028
CVE-2011-10035
Nagios XI < 2011R1.9 Race Conditions in Crontab Install Scripts LPE
Published 2025-10-30 · Analyzed
7.3EPSS 0.002
CVE-2021-3277
Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rename functionality in custom-includes component, which leads to remote code execution by uploading php files.
Published 2021-06-07 · Modified
7.2EPSS 0.546
CVE-2018-10735
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/commandline.php cname parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2018-10736
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/info.php key1 parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2018-10737
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2018-10738
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/menuaccess.php chbKey1 parameter.
Published 2018-05-16 · Modified
7.2EPSS 0.421
CVE-2023-40934
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
Published 2023-09-19 · Modified
7.2EPSS 0.024
CVE-2013-10072
Nagios XI < 2012R1.6 Auto-Discovery Missing Authorization
Published 2025-10-30 · Analyzed
7.2EPSS 0.007
CVE-2024-14002
Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis
Published 2025-10-30 · Analyzed
7.1EPSS 0.012
← Prev2 / 4Next →