Search CVE reports
71 – 80 of 42336 results
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string values reflected from stored fields are inserted into the DOM without sanitization,...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by...
1 affected package
nagios4
| Package | 24.04 LTS |
|---|---|
| nagios4 | Needs evaluation |
cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations...
1 affected package
cjson
| Package | 24.04 LTS |
|---|---|
| cjson | Needs evaluation |
CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both...
1 affected package
civetweb
| Package | 24.04 LTS |
|---|---|
| civetweb | Needs evaluation |
Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |
Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with...
1 affected package
intel-microcode
| Package | 24.04 LTS |
|---|---|
| intel-microcode | Needs evaluation |