Vulnerabilities (CVE)

Filtered by vendor Pnp4nagios Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38349 1 Pnp4nagios 1 Pnp4nagios 2023-07-26 N/A 8.8 HIGH
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
CVE-2017-16834 1 Pnp4nagios 1 Pnp4nagios 2019-10-03 7.2 HIGH 7.8 HIGH
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allows local users to gain privileges by leveraging access to this unprivileged account.