Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 302 respecto a la semana anterior
Críticas / altas1389▼ 21 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)1.5%—Nagios XI14/10/202417/6/2026
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.
ModificadaAlta (8.8)1.4%💥 PoCNagios XI1/5/202424/8/2026
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
ModificadaCrítica (9.8)3.4%💥 PoCNagios XI26/2/202417/6/2026
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.
AnalizadaCrítica (9.8)46%💥 PoCNagios XI26/2/202417/6/2026
SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.
ModificadaMedia (5.4)1.3%—Nagios XI2/2/202417/6/2026
A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious HTML or JavaScript code via the audio file upload functionality from the Operation Center section. This allows any authenticated user to execute…
ModificadaCrítica (9.8)76%—Nagios XI14/12/202317/6/2026
Nagios XI before version 5.11.3 was discovered to contain a remote code execution (RCE) vulnerability via the component command_test.php.
ModificadaCrítica (9.8)34%💥 ExploitNagios XI14/12/202317/6/2026
Nagios XI before version 5.11.3 was discovered to contain a SQL injection vulnerability via the bulk modification tool.
ModificadaAlta (7.2)2.4%—Nagios XI19/9/20239/7/2026
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
ModificadaAlta (8.8)3.5%💥 PoCNagios XI19/9/20239/7/2026
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
ModificadaMedia (5.4)0.86%—Nagios XI19/9/20239/7/2026
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able…
ModificadaMedia (6.5)12%💥 ExploitNagios XI19/9/20239/7/2026
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
ModificadaMedia (6.1)2.5%—Nagios XI22/8/202317/6/2026
Cross Site Scripting (XSS) in Nagios XI 5.7.1 allows remote attackers to run arbitrary code via returnUrl parameter in a crafted GET request.
ModificadaMedia (6.1)2.1%—Nagios XI7/9/202217/6/2026
Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in CCM 3.1.5.
ModificadaMedia (4.8)2.1%—Nagios XI7/9/202217/6/2026
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Settings page under the Admin panel.
ModificadaCrítica (9.8)3.0%—Nagios XI7/9/202217/6/2026
Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page.
ModificadaMedia (6.1)2.1%—Nagios XI7/9/202217/6/2026
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1.0.4.
ModificadaMedia (6.1)2.1%—Nagios XI7/9/202217/6/2026
Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
ModificadaMedia (4.8)2.1%—Nagios XI7/9/202217/6/2026
Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under the Admin panel.
ModificadaMedia (6.1)4.1%💥 ExploitNagios XI29/6/202217/6/2026
In Nagios XI through 5.8.5, an open redirect vulnerability exists in the login function that could lead to spoofing.
ModificadaMedia (6.5)2.0%—Nagios XI29/6/202217/6/2026
In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.
ModificadaMedia (4.3)3.4%—Nagios XI29/6/202217/6/2026
In Nagios XI through 5.8.5, it is possible for a user without password verification to change his e-mail address.
ModificadaMedia (6.5)3.0%—Nagios XI29/6/202217/6/2026
In Nagios XI through 5.8.5, in the schedule report function, an authenticated attacker is able to inject HTML tags that lead to the reformatting/editing of emails from an official email address.
ModificadaAlta (7.2)23%💥 PoCNagios XI26/10/202117/6/2026
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute system commands.
ModificadaAlta (7.2)65%—Nagios XI26/10/202117/6/2026
An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can upload files with arbitrary extensions as long as the MIME type corresponds to an image. Therefore it is possible to upload a crafted PHP script to achieve remote command execution.
ModificadaAlta (7.8)0.65%—Nagios XI26/10/202117/6/2026
An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios user to elevate their privileges to the root user.
Orbitaley — Vulnerabilidades