VendorsNagiosnagios_xi2024
Vulnerabilities

Nagios Nagios Xi 2024

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2024-24401
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
Published 2024-02-26 · Analyzed
9.8EPSS 0.459
CVE-2024-24402
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
Published 2024-02-26 · Modified
9.8EPSS 0.034
CVE-2024-14003
Nagios XI < 2024R1.2 RCE via NRDP Server Plugins
Published 2025-10-30 · Analyzed
9.8EPSS 0.021
CVE-2024-13999
Nagios XI < 2024R1.1.3 AD/LDAP Token Authenticated Information Disclosure
Published 2025-10-30 · Analyzed
9.8EPSS 0.018
CVE-2024-13996
Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change
Published 2025-10-30 · Analyzed
9.8EPSS 0.010
CVE-2024-13994
Nagios XI < 2024R1.1.2 Allow Insecure Logins Missing Authorization
Published 2025-10-30 · Analyzed
9.8EPSS 0.009
CVE-2024-14005
Nagios XI < 2024R1.2 Command Injection via Docker Wizard
Published 2025-10-30 · Analyzed
9.4EPSS 0.041
CVE-2025-34284
Nagios XI < 2024R2 Authenticated Command Injection via WinRM Plugin
Published 2025-10-30 · Analyzed
9.4EPSS 0.041
CVE-2024-14008
Nagios XI < 2024R1.3.2 RCE via WinRM Configuration Wizard
Published 2025-10-30 · Analyzed
9.4EPSS 0.022
CVE-2025-34134
Nagios XI < 2024R1.4.2 RCE via Business Process Intelligence (BPI)
Published 2025-10-30 · Analyzed
9.4EPSS 0.022
CVE-2024-13997
Nagios XI < 2024R1.1.3 Privilege Escalation via Migrate Server Feature to Root on Host
Published 2025-11-03 · Analyzed
9.4EPSS 0.011
CVE-2024-14009
Nagios XI < 2024R1.0.1 Privilege Escalation via System Profile
Published 2025-10-30 · Analyzed
9.4EPSS 0.011
CVE-2024-13986
Nagios XI < 2024R1.3.2 Authenticated Arbitrary File Upload Path Traversal RCE
Published 2025-08-28 · Modified
8.8EPSS 0.017
CVE-2024-33775
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
Published 2024-05-01 · Modified
8.8EPSS 0.014
CVE-2024-13995
Nagios XI < 2024R1.1.2 API Keys & Hashed Passwords Authenticated Information Disclosure
Published 2025-10-30 · Analyzed
8.8EPSS 0.012
CVE-2024-14004
Nagios XI < 2024R1.2 Privilege Escalation via NagVis Configuration (nagvis.conf)
Published 2025-10-30 · Analyzed
8.8EPSS 0.010
CVE-2024-14006
Nagios XI < 2024R1.2.2 Host Header Injection
Published 2025-10-30 · Analyzed
8.8EPSS 0.004
CVE-2025-34287
Nagios XI < 2024R2 Privilege Escalation via process_perfdata.pl
Published 2025-10-30 · Analyzed
8.4EPSS 0.003
CVE-2024-14002
Nagios XI < 2024R1.1.4 Authenticated Local File Inclusion via NagVis
Published 2025-10-30 · Analyzed
7.1EPSS 0.012
CVE-2025-34283
Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes
Published 2025-10-30 · Analyzed
7.1EPSS 0.010
CVE-2024-54961
Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users.
Published 2025-02-20 · Analyzed
6.5EPSS 0.016
CVE-2024-54960
A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted payload in the History Tab component.
Published 2025-02-20 · Analyzed
6.5EPSS 0.014
CVE-2024-13998
Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure
Published 2025-11-03 · Analyzed
6.5EPSS 0.010
CVE-2024-54959
Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabling POST-based Cross-Site Scripting (XSS).
Published 2025-02-20 · Analyzed
6.1EPSS 0.010
CVE-2024-54958
Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw allows an attacker to inject malicious scripts into the Tools interface, which are then stored and executed in the context of other users accessing the page.
Published 2025-02-20 · Analyzed
6.1EPSS 0.010
CVE-2025-56432
A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute arbitrary JavaScript in the context of a logged-in user's session via a specially crafted URL. The issue resides in a web component responsible for rendering performance-related data.
Published 2025-08-26 · Modified
6.1EPSS 0.009
CVE-2024-13993
Nagios XI < 2024R1.1.2 Reflected XSS via Login Page on Older Browsers
Published 2025-10-30 · Analyzed
6.1EPSS 0.007
CVE-2024-54957
Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.
Published 2025-02-27 · Analyzed
6.1EPSS 0.006
CVE-2023-51072
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute arbitrary JavaScript code on behalf of other users, including the administrators.
Published 2024-02-02 · Modified
5.4EPSS 0.013
CVE-2024-42898
A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.
Published 2025-01-09 · Analyzed
5.4EPSS 0.006
CVE-2024-14001
Nagios XI < 2024R1.1.3 XSS via Executive Summary Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2024-14000
Nagios XI < 2024R1.1.3 XSS via Capacity Planning Report
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2024-13992
Nagios XI < 2024R1.1 XSS via Missing Page / 404
Published 2025-10-31 · Analyzed
5.4EPSS 0.005
CVE-2023-7318
Nagios XI < 2024R1.0.2 XSS via Core Command Expansion
Published 2025-10-30 · Analyzed
5.4EPSS 0.005
CVE-2025-34135
Nagios XI < 2024R1.4.2 Overly Permissive Permissions on Systemd Unit Files
Published 2025-10-30 · Analyzed
5.1EPSS 0.003