Search Results (303 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2016-8641 1 Nagios 1 Nagios 2024-11-21 N/A
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.
CVE-2015-3618 1 Nagios 1 Business Process Intelligence 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in Nagios Business Process Intelligence (BPI) before 2.3.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving index.php.
CVE-2023-37154 1 Nagios 1 Plugins 2024-10-10 8.4 High
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.