« Volver al listado

Nagios

Nagios XI: vulnerabilidades y CVE

Nagios XI tiene 200 vulnerabilidades publicadas, 91 de ellas en los últimos 12 meses. 32 son críticas y 4 figuran en el catálogo de explotación activa de CISA.

CVE200
Últimos 12 meses91
Críticas32
Explotadas activamente4

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2021-25297Alta (8.8)57%⚠ Explotación activa15 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated…
CVE-2021-25296Alta (8.8)72%⚠ Explotación activa15 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of…
CVE-2021-25298Alta (8.8)75%⚠ Explotación activa15 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of…
CVE-2019-15949Alta (8.8)77%⚠ Explotación activa5 sept 2019
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2023-24035Baja (3.5)0.77%—14 sept 2026
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring…
CVE-2023-24034Baja (3.1)0.53%—14 sept 2026
An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
CVE-2026-48549Media (6.9)0.26%—26 ago 2026
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header is present, the double-submit cookie protection can be bypassed by supplying matching NagFormId and…
CVE-2026-48554Alta (7.7)0.97%—12 ago 2026
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification…
CVE-2026-48553Alta (7.7)0.97%—12 ago 2026
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable…
CVE-2026-48552Media (5.1)0.29%—12 ago 2026
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without…
CVE-2026-48551Media (6.1)0.26%—12 ago 2026
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter…
CVE-2026-48550Media (5.1)0.44%—12 ago 2026
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when…
CVE-2026-2043Alta (8.8)74%—20 feb 2026
Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host.…
CVE-2026-2042Alta (8.8)5.6%—20 feb 2026
Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is…
CVE-2026-2041Alta (8.8)74%—20 feb 2026
Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host.…
CVE-2025-67255Alta (8.8)1.1%—29 dic 2025
In NagiosXI 2026R1.0.1 build 1762361101, Dashboard parameters lack proper filtering, allowing any authenticated user to exploit a SQL Injection vulnerability.
CVE-2025-67254Alta (7.5)2.0%—29 dic 2025
NagiosXI 2026R1.0.1 build 1762361101 is vulnerable to Directory Traversal in /admin/coreconfigsnapshots.php.
CVE-2025-34288Alta (8.6)1.9%—16 dic 2025
Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between sudo permissions and application file permissions. A user‑accessible maintenance script may be…
CVE-2021-47698Media (5.1)0.44%—3 nov 2025
Nagios XI versions prior to 5.8.7 using embedded Nagios Core are vulnerable to cross-site scripting (XSS) via the Core UI’s Views URL handling (escape_string()). Insufficient validation or escaping of user-supplied…
CVE-2024-13998Media (6)1.0%—3 nov 2025
Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data.…
CVE-2024-13997Crítica (9.4)1.2%—3 nov 2025
Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrator could leverage the Migrate Server feature to obtain root privileges on the underlying XI host.…
CVE-2024-13992Media (5.1)0.59%—31 oct 2025
Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component,…
CVE-2025-34287Alta (8.4)0.29%—30 oct 2025
Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker…
CVE-2025-34286Crítica (9.4)2.4%—30 oct 2025
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters used to build backend command lines…
CVE-2023-7318Media (5.1)0.59%—30 oct 2025
Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of user-supplied input may allow an attacker to…
CVE-2023-7317Crítica (9.4)1.7%—30 oct 2025
Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact with the terminal interface without sufficient…
CVE-2023-7316Media (5.1)0.59%—30 oct 2025
Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…
CVE-2023-7315Media (5.1)0.51%—30 oct 2025
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…
CVE-2023-7314Media (5.1)0.48%—30 oct 2025
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…
CVE-2023-7313Media (5.1)0.48%—30 oct 2025
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…
CVE-2023-53688Media (5.1)0.32%—30 oct 2025
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can submit crafted input that is not properly…
CVE-2022-50588Media (5.1)0.44%—30 oct 2025
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute…
CVE-2022-50587Media (5.1)0.44%—30 oct 2025
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and…
CVE-2022-50586Media (5.1)0.44%—30 oct 2025
Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services40
  2. T1059 Command and Scripting Interpreter20
  3. T1005 Data from Local System9
  4. T1068 Exploitation for Privilege Escalation8
  5. T1078 Valid Accounts4
  6. T1190 Exploit Public-Facing Application4

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Nagios