Search CVE reports


Toggle filters

11 – 20 of 72 results


CVE-2022-38251

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.

3 affected packages

icinga, nagios4, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38250

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.

3 affected packages

icinga, nagios4, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38249

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.

3 affected packages

icinga, nagios4, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38248

Medium priority
Needs evaluation

Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.

3 affected packages

icinga, nagios4, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2022-38247

Medium priority
Needs evaluation

Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.

3 affected packages

icinga, nagios4, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 Not in release Not in release Needs evaluation
Show less packages

CVE-2020-35269

Medium priority
Needs evaluation

Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2020-13977

Medium priority
Needs evaluation

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Not affected Not affected Not affected Needs evaluation Not in release
Show less packages

CVE-2020-6582

Low priority
Vulnerable

Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.

1 affected package

nagios-nrpe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios-nrpe Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2020-6581

Low priority
Vulnerable

Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.

1 affected package

nagios-nrpe

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios-nrpe Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2019-3698

Medium priority
Not affected

UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 11; openSUSE Factory allows local attackers to cause cause DoS or potentially...

2 affected packages

icinga, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga Not affected
nagios3 Not affected
Show less packages