Filtered by vendor Nagios Subscriptions
Filtered by product Xi Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2012-10029 1 Nagios 3 Nagios, Nagios Xi, Xi 2025-08-06 N/A
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `visApi.php`. An authenticated user can inject system commands via unsanitized parameters such as `host`, resulting in remote code execution.
CVE-2023-48082 1 Nagios 2 Nagios Xi, Xi 2025-07-10 9.1 Critical
Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for all users and utilize them to authenticate.