Search CVE reports


Toggle filters

1 – 10 of 40 results


CVE-2022-38254

Medium priority
Needs evaluation

Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

3 affected packages

nagios4, icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38251

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

3 affected packages

nagios4, icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38250

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

3 affected packages

nagios4, icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38249

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

3 affected packages

nagios4, icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38248

Medium priority
Needs evaluation

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

3 affected packages

nagios4, icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
icinga Not in release Not in release Needs evaluation
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38247

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

3 affected packages

nagios4, nagios3, icinga

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 Not in release Not in release Needs evaluation
icinga Not in release Not in release Needs evaluation
Show less packages

CVE-2019-3698

Medium priority
Not affected

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially...

2 affected packages

icinga, nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not affected
nagios3 Not affected
Show less packages

CVE-2018-8736

High priority
Not affected

A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escalating to root.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-8735

High priority
Not affected

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command injection.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages

CVE-2018-8734

Medium priority
Not affected

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

1 affected package

nagios3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios3
Show less packages