Known Vulnerabilities for products from Pnp4nagios
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Pnp4nagios".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-38350 json | PNP4Nagios through 81ebfc5 has stored XSS in the AJAX controller via the basket API and filters. This affects 0.6.26. | 5.4 - MEDIUM | 2023-07-15 | 2023-07-26 |
| CVE-2023-38349 json | PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26. | 8.8 - HIGH | 2023-07-15 | 2023-07-26 |
| CVE-2017-16834 json | PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on ... | Not Provided | 2017-11-16 | 2025-04-20 |
| CVE-2014-4908 json | Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary w... | Not Provided | 2014-07-11 | 2026-05-06 |
| CVE-2014-4907 json | Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 all... | Not Provided | 2014-07-11 | 2026-05-06 |
| CVE-2012-3457 json | PNP4Nagios 0.6 through 0.6.16 uses world-readable permissions for process_perfdata.cfg, which allows local users to obtain th... | Not Provided | 2012-08-12 | 2026-04-29 |
Known software with vulnerabilities from Pnp4nagios
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Pnp4nagios | Pnp4nagios | 0.6.0 |