Search CVE reports


Toggle filters

1 – 10 of 72 results


CVE-2026-48549

Medium priority
Needs evaluation

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and nagFormId...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-48548

Medium priority
Needs evaluation

Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mechanism passes validation when the NagFormId cookie is absent. Attackers can craft a malicious cross-site POST...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-48554

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-48553

Medium priority
Needs evaluation

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-48552

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-48551

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-48550

Medium priority
Needs evaluation

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by...

1 affected package

nagios4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2023-38350

Medium priority
Ignored

PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26.

1 affected package

pnp4nagios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pnp4nagios — — Not in release Not in release Not in release
Show less packages

CVE-2023-38349

Medium priority
Ignored

PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.

1 affected package

pnp4nagios

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
pnp4nagios — — Not in release Not in release Not in release
Show less packages

CVE-2022-38254

Medium priority
Needs evaluation

Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.

3 affected packages

icinga, nagios4, nagios3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
icinga — — Not in release Not in release Needs evaluation
nagios4 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
nagios3 — — Not in release Not in release Needs evaluation
Show less packages