CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

nagios

nagios_xi

191 known vulnerabilities · sorted by CVSS score

CVE-2024-33775
CRITICAL9.8

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

nagios / nagios_xi
Network
Published May 1, 2024
Page 1 of 10
CVE-2021-36365
CRITICAL9.8

Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh.

nagios / nagios_xi
Network
Published Sep 28, 2021
CVE-2018-17148
CRITICAL9.8

An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.

nagios / nagios_xi
Network
Published Jun 19, 2019
CVE-2018-8733
CRITICAL9.8

Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an unauthenticated attacker to make configuration changes and leverage an authenticated SQL injection vulnerability.

nagios / nagios_xi
Network
Published Apr 18, 2018
CVE-2024-13999
CRITICAL9.8

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.

nagios / nagios_xi+6
Network
Published Oct 30, 2025
CVE-2020-28910
CRITICAL9.8

Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of symlinks, which are mishandled in getprofile.sh.

nagios / nagios_xi
Network
Published May 24, 2021
CVE-2024-24402
CRITICAL9.8

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

nagios / nagios_xi
Network
Published Feb 26, 2024
CVE-2024-24401
CRITICAL9.8

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

nagios / nagios_xi
Network
Published Feb 26, 2024
CVE-2021-36364
CRITICAL9.8

Nagios XI before 5.8.5 incorrectly allows backup_xi.sh wildcards.

nagios / nagios_xi
Network
Published Sep 28, 2021
CVE-2019-9165
CRITICAL9.8

SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API when using fusekeys and malicious user id.

nagios / nagios_xi
Network
Published Mar 28, 2019
CVE-2024-13996
CRITICAL9.8

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.

nagios / nagios_xi+6
Network
Published Oct 30, 2025
CVE-2019-12279
CRITICAL9.8

Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). NOTE: The vendor disputes this issues as not being a vulnerability because the issue does not seem to be a legitimate SQL Injection. The POC does not show any valid injection that can be done with the variable provided, and while the username value being passed does get used in a SQL query, it is passed through SQL escaping functions when creating the call. The vendor tried re-creating the issue with no luck

nagios / nagios_xi
Network
Published May 22, 2019
CVE-2021-3193
CRITICAL9.8

Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7, allows an unauthenticated attacker to execute remote code as the apache user.

nagios / nagios_xi
Network
Published Jan 26, 2021
CVE-2023-48084
CRITICAL9.8

Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.

nagios / nagios_xi
Network
Published Dec 14, 2023
CVE-2021-37350
CRITICAL9.8

Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper input sanitisation.

nagios / nagios_xi
Network
Published Aug 13, 2021
CVE-2018-8734
CRITICAL9.8

SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary SQL commands via the selInfoKey1 parameter.

nagios / nagios_xi
Network
Published Apr 18, 2018
CVE-2018-15708
CRITICAL9.8

Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

nagios / nagios_xi
Network
Published Nov 14, 2018
CVE-2012-10063
CRITICAL9.8

Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQL queries by supplying crafted input to specific CCM parameters, potentially allowing access to configuration data stored in the application database. Successful exploitation could disclose or modify notification data and, in some cases, impact the application database more broadly.

nagios / nagios_xi+3
Network
Published Oct 30, 2025
CVE-2024-13994
CRITICAL9.8

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper authorization. This can lead to unauthorized account creation, privilege escalation, or full compromise of the Nagios XI web interface depending on the target account.

nagios / nagios_xi+5
Network
Published Oct 30, 2025
CVE-2021-36363
CRITICAL9.8

Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php.

nagios / nagios_xi
Network
Published Sep 28, 2021