Nagios kayıtları
nagios üreticisine ait 302 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %1,3
- Silahlaştırılmış
- 17 · %5,6
- Pre-auth RCE
- 29
- Düzeltme kaydı olan
- %28,1
- Yayından KEV’e ortanca
- 337 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')109
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')31
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')27
- CWE-732 Incorrect Permission Assignment for Critical Resource9
- CWE-269 Improper Privilege Management9
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
302 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
88Hemen | CVE-2019-15949Silahlaştırılmış | Nagios XI before 5.6.6 allows remote command execution as root.nagios · nagios xi · CWE-78 | Yüksek8,8 | KEV | %77,0 | 5 Eyl 2019 |
88Hemen | CVE-2021-25298Silahlaştırılmış | Nagios XI version xi-5.7.5 is affected by OS command injection.nagios · nagios xi · CWE-78 | Yüksek8,8 | KEV | %75,1 | 15 Şub 2021 |
87Hemen | CVE-2021-25296Silahlaştırılmış | Nagios XI version xi-5.7.5 is affected by OS command injection.nagios · nagios xi | Yüksek8,8 | KEV | %72,2 | 15 Şub 2021 |
82Hemen | CVE-2021-25297Silahlaştırılmış | Nagios XI version xi-5.7.5 is affected by OS command injection.nagios · nagios xi · CWE-78 | Yüksek8,8 | KEV | %56,7 | 15 Şub 2021 |
68Bu hafta | CVE-2021-37344İstismar yok | Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements usednagios · nagios xi switch wizard · CWE-78 | Kritik9,8 | — | %96,8 | 13 Ağu 2021 |
66Bu hafta | CVE-2018-15708Silahlaştırılmış | Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.nagios · nagios xi | Kritik9,8 | — | %89,4 | 14 Kas 2018 |
63Bu hafta | CVE-2021-37350İstismar yok | Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.nagios · nagios xi · CWE-89 | Kritik9,8 | — | %79,3 | 13 Ağu 2021 |
62Bu hafta | CVE-2023-48085İstismar yok | Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.nagios · nagios xi · CWE-94 | Kritik9,8 | — | %75,8 | 14 Ara 2023 |
61Bu hafta | CVE-2021-37346İstismar yok | Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements nagios · nagios xi watchguard wizard · CWE-78 | Kritik9,8 | — | %73,6 | 13 Ağu 2021 |
57Planlayın | CVE-2026-2041İstismar yok | Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerabilitynagios · nagios xi · CWE-78 | Yüksek8,8 | — | %73,7 | 20 Şub 2026 |
57Planlayın | CVE-2026-2043İstismar yok | Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerabilitynagios · nagios xi · CWE-78 | Yüksek8,8 | — | %73,7 | 20 Şub 2026 |
55Planlayın | CVE-2009-2288Silahlaştırılmış | statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Tnagios · nagios · CWE-78 | Yüksek7,5 | — | %83,5 | 1 Tem 2009 |
55Planlayın | CVE-2018-8734Silahlaştırılmış | SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrarnagios · nagios xi · CWE-89 | Kritik9,8 | — | %53,8 | 17 Nis 2018 |
54Planlayın | CVE-2018-8735Silahlaştırılmış | Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commandsnagios · nagios xi · CWE-78 | Yüksek8,8 | — | %63,6 | 17 Nis 2018 |
53Planlayın | CVE-2021-25299Kavram kanıtı | Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS).nagios · nagios xi · CWE-79 | Orta6,1 | — | %97,8 | 15 Şub 2021 |
53Planlayın | CVE-2020-35578Silahlaştırılmış | An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0.nagios · nagios xi · CWE-78 | Yüksek7,2 | — | %81,9 | 13 Oca 2021 |
53Planlayın | CVE-2024-24401Kavram kanıtı | SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitorinnagios · nagios xi · CWE-89 | Kritik9,8 | — | %45,9 | 26 Şub 2024 |
52Planlayın | CVE-2020-5791Silahlaştırılmış | Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute opnagios · nagios xi · CWE-78 | Yüksek7,2 | — | %78,6 | 20 Eki 2020 |
50Planlayın | CVE-2012-6096Silahlaştırılmış | Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,nagios · nagios · CWE-119 | Yüksek7,5 | — | %66,5 | 22 Oca 2013 |
50Planlayın | CVE-2013-1362Silahlaştırılmış | Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arnagios · remote plug in executor · CWE-20 | Yüksek7,5 | — | %65,7 | 9 Tem 2013 |
49Planlayın | CVE-2021-38156Kavram kanıtı | In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.nagios · nagios xi · CWE-79 | Orta5,4 | — | %92,9 | 15 Eyl 2021 |
49Planlayın | CVE-2019-9164İstismar yok | Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.nagios · nagios xi · CWE-79 | Yüksek8,8 | — | %46,0 | 28 Mar 2019 |
49Planlayın | CVE-2018-8736Silahlaştırılmış | A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability escanagios · nagios xi | Yüksek8,8 | — | %45,6 | 17 Nis 2018 |
49Planlayın | CVE-2023-48084Kavram kanıtı | Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.nagios · nagios xi · CWE-89 | Kritik9,8 | — | %34,0 | 14 Ara 2023 |
48Planlayın | CVE-2020-27988İstismar yok | Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).nagios · nagios xi · CWE-79 | Orta5,4 | — | %91,3 | 16 Kas 2020 |
- CVE-2019-1594988Hemen
Nagios XI before 5.6.6 allows remote command execution as root.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %77nagios · nagios xi5 Eyl 2019
- CVE-2021-2529888Hemen
Nagios XI version xi-5.7.5 is affected by OS command injection.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %75nagios · nagios xi15 Şub 2021
- CVE-2021-2529687Hemen
Nagios XI version xi-5.7.5 is affected by OS command injection.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %72nagios · nagios xi15 Şub 2021
- CVE-2021-2529782Hemen
Nagios XI version xi-5.7.5 is affected by OS command injection.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %57nagios · nagios xi15 Şub 2021
- CVE-2021-3734468Bu hafta
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used
KritikCVSS 9,8İstismar yokEPSS %97nagios · nagios xi switch wizard13 Ağu 2021
- CVE-2018-1570866Bu hafta
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
KritikCVSS 9,8SilahlaştırılmışEPSS %89nagios · nagios xi14 Kas 2018
- CVE-2021-3735063Bu hafta
Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.
KritikCVSS 9,8İstismar yokEPSS %79nagios · nagios xi13 Ağu 2021
- CVE-2023-4808562Bu hafta
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.
KritikCVSS 9,8İstismar yokEPSS %76nagios · nagios xi14 Ara 2023
- CVE-2021-3734661Bu hafta
Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation of special elements
KritikCVSS 9,8İstismar yokEPSS %74nagios · nagios xi watchguard wizard13 Ağu 2021
- CVE-2026-204157Planlayın
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %74nagios · nagios xi20 Şub 2026
- CVE-2026-204357Planlayın
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %74nagios · nagios xi20 Şub 2026
- CVE-2009-228855Planlayın
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) T
YüksekCVSS 7,5SilahlaştırılmışEPSS %83nagios · nagios1 Tem 2009
- CVE-2018-873455Planlayın
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrar
KritikCVSS 9,8SilahlaştırılmışEPSS %54nagios · nagios xi17 Nis 2018
- CVE-2018-873554Planlayın
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands
YüksekCVSS 8,8SilahlaştırılmışEPSS %64nagios · nagios xi17 Nis 2018
- CVE-2021-2529953Planlayın
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS).
OrtaCVSS 6,1Kavram kanıtıEPSS %98nagios · nagios xi15 Şub 2021
- CVE-2020-3557853Planlayın
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0.
YüksekCVSS 7,2SilahlaştırılmışEPSS %82nagios · nagios xi13 Oca 2021
- CVE-2024-2440153Planlayın
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitorin
KritikCVSS 9,8Kavram kanıtıEPSS %46nagios · nagios xi26 Şub 2024
- CVE-2020-579152Planlayın
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admin user to execute op
YüksekCVSS 7,2SilahlaştırılmışEPSS %79nagios · nagios xi20 Eki 2020
- CVE-2012-609650Planlayın
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,
YüksekCVSS 7,5SilahlaştırılmışEPSS %66nagios · nagios22 Oca 2013
- CVE-2013-136250Planlayın
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute ar
YüksekCVSS 7,5SilahlaştırılmışEPSS %66nagios · remote plug in executor9 Tem 2013
- CVE-2021-3815649Planlayın
In Nagios XI before 5.8.6, XSS exists in the dashboard page (/dashboards/#) when administrative users attempt to edit a dashboard.
OrtaCVSS 5,4Kavram kanıtıEPSS %93nagios · nagios xi15 Eyl 2021
- CVE-2019-916449Planlayın
Command injection in Nagios XI before 5.5.11 allows an authenticated users to execute arbitrary remote commands via a new autodiscovery job.
YüksekCVSS 8,8İstismar yokEPSS %46nagios · nagios xi28 Mar 2019
- CVE-2018-873649Planlayın
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RCE vulnerability esca
YüksekCVSS 8,8SilahlaştırılmışEPSS %46nagios · nagios xi17 Nis 2018
- CVE-2023-4808449Planlayın
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
KritikCVSS 9,8Kavram kanıtıEPSS %34nagios · nagios xi14 Ara 2023
- CVE-2020-2798848Planlayın
Nagios XI before 5.7.5 is vulnerable to XSS in Manage Users (Username field).
OrtaCVSS 5,4İstismar yokEPSS %91nagios · nagios xi16 Kas 2020