← Back

Nagios Core

nagios_core

Vendor: Nagios • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nagios
1Nagios Core
Jun 17, 2026
Dec 23, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
2Debian
Nagios
2Debian Linux
Nagios Core
Nov 21, 2024
Dec 17, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
1Nagios
1Nagios Core
Nov 21, 2024
Jul 12, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket...Show more
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.Show less
1Nagios
1Nagios Core
Nov 21, 2024
Jul 12, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket...Show more
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.Show less
1Nagios
1Nagios Core
May 13, 2026
Sep 11, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account),...Show more
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account.Show less