CVE Database

54235+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-14006
6.1 MEDIUM

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without …

Oct 30, 2025
CVE-2024-14002
5.5 MEDIUM

Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values …

Oct 30, 2025
CVE-2024-14001
5.4 MEDIUM

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2024-14000
5.4 MEDIUM

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2024-13993
6.1 MEDIUM

Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. …

Oct 30, 2025
CVE-2023-7323
5.4 MEDIUM

Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2023-7321
5.4 MEDIUM

Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for …

Oct 30, 2025
CVE-2023-7319
5.4 MEDIUM

Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2023-7318
5.4 MEDIUM

Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2023-7316
5.4 MEDIUM

Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7315
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7314
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7313
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7312
4.8 MEDIUM

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability when adding or configuring Email Settings. Unsanitized user input can be stored …

Oct 30, 2025
CVE-2023-53690
4.8 MEDIUM

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and …

Oct 30, 2025
CVE-2023-53689
4.8 MEDIUM

Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the license key configuration flow that can result in execution of …

Oct 30, 2025
CVE-2023-53688
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can …

Oct 30, 2025
CVE-2022-50588
5.4 MEDIUM

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2022-50587
5.4 MEDIUM

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2022-50586
5.4 MEDIUM

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping …

Oct 30, 2025
CVE-2022-50585
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.7 / Nagios XI 5.8.9 contains a cross-site scripting (XSS) vulnerability via the …

Oct 30, 2025
CVE-2022-50584
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.6 / Nagios XI 5.8.8 contains a cross-site scripting (XSS) vulnerability via the …

Oct 30, 2025
CVE-2021-47699
5.4 MEDIUM

Nagios XI versions prior to 5.8.7 are vulnerable to cross-site scripting (XSS) via the Audit Log page’s Send to NLS form. Insufficient validation or escaping …

Oct 30, 2025
CVE-2021-47697
5.4 MEDIUM

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via the Views feature URL handling. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2021-47696
5.4 MEDIUM

Nagios XI versions prior to 5.8.0 are vulnerable to cross-site scripting (XSS) via BPI config ID handling. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2021-47695
5.4 MEDIUM

Nagios XI versions prior to 5.8.0 are vulnerable to stored cross-site scripting (XSS) via the My Tools page. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2021-47694
6.1 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.4 / Nagios XI 5.8.6 contains a reflected cross-site scripting (XSS) vulnerability via …

Oct 30, 2025
CVE-2021-47691
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities via the …

Oct 30, 2025
CVE-2021-47690
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.1 / Nagios XI 5.8.2 contains multiple cross-site scripting (XSS) vulnerabilities in Overlay …

Oct 30, 2025
CVE-2021-47689
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.1.0 / Nagios XI 5.8.0 contais a cross-site scripting (XSS) vulnerability in the …

Oct 30, 2025
CVE-2020-36866
5.4 MEDIUM

Nagios XI versions prior to 5.7.3 are vulnerable to cross-site scripting (XSS) via the Manage Users page of the Admin interface. Insufficient validation or escaping …

Oct 30, 2025
CVE-2020-36865
5.4 MEDIUM

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the BPI (Business Process Intelligence) component’s Config Management and Edit Config page. …

Oct 30, 2025
CVE-2020-36864
5.4 MEDIUM

Nagios XI versions prior to 5.7.2 are vulnerable to cross-site scripting (XSS) via the background color settings in Dashboards. Insufficient validation or escaping of user-supplied …

Oct 30, 2025
CVE-2020-36862
6.1 MEDIUM

Nagios XI versions prior to 5.6.11 contain unauthenticated vulnerabilities in the Highcharts local exporting tool. Crafted export requests could (1) inject script into exported/returned content …

Oct 30, 2025
CVE-2020-36861
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.8 / Nagios XI 5.7.5 contains multiple cross-site scripting (XSS) vulnerabilities in the …

Oct 30, 2025
CVE-2020-36860
5.4 MEDIUM

The Core Config Manager (CCM) in Nagios XI versions prior to CCM 3.0.7 / Nagios XI 5.7.4 contains multiple cross-site scripting (XSS) vulnerabilities in the …

Oct 30, 2025
CVE-2020-36858
5.4 MEDIUM

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host …

Oct 30, 2025
CVE-2018-25121
5.4 MEDIUM

Nagios XI versions prior to 5.4.13 are vulnerable to cross-site scripting (XSS) via the Views page of the web interface. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2018-25119
6.1 MEDIUM

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow …

Oct 30, 2025
CVE-2017-20209
6.1 MEDIUM

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2016-15053
5.4 MEDIUM

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web interface. Insufficient validation or escaping …

Oct 30, 2025
CVE-2016-15052
5.4 MEDIUM

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2016-15051
5.4 MEDIUM

Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values from the startdate and enddate fields. Insufficient …

Oct 30, 2025
CVE-2016-15049
5.4 MEDIUM

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. …

Oct 30, 2025
CVE-2013-10074
5.4 MEDIUM

Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2013-10072
6.5 MEDIUM

Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages …

Oct 30, 2025
CVE-2013-10071
6.1 MEDIUM

Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2011-10040
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the link-handling functions used by status and report pages. Insufficient validation or …

Oct 30, 2025
CVE-2011-10039
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the Alert Heatmap report and the “My Reports” listing of the web …

Oct 30, 2025
CVE-2011-10038
5.4 MEDIUM

Nagios XI versions prior to 2011R1.9 are vulnerable to cross-site scripting (XSS) via the recurring downtime script of the web interface. Insufficient validation or escaping …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.