A vulnerability was found in Nagios XI up to 2012R1.2. It has been rated as critical. The impacted element is an unknown function of the component Legacy Core Configuration Manager. Performing manipulation results in sql injection.
This vulnerability is known as CVE-2012-10063. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in Nagios XI up to 5.7.3. Affected is an unknown function of the component Object Edit Page. The manipulation results in sql injection.
This vulnerability was named CVE-2020-36859. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability described as problematic has been identified in Nagios XI up to 5.7.x. The impacted element is an unknown function of the component Core Config Manager. The manipulation results in cross site scripting.
This vulnerability was named CVE-2021-47689. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability has been found in Nagios XI up to 2011R1.8 and classified as problematic. Affected by this issue is some unknown functionality of the component Link Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2011-10040. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability described as problematic has been identified in Nagios XI up to 5.7.1. This affects an unknown part of the component Manage Users Page. Executing manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2020-36866. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Nagios XI up to 5.7.3. This issue affects some unknown processing of the component Object Edit Page. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2020-36860. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability described as problematic has been identified in Nagios XI up to 5.7.4. Impacted is an unknown function of the component Check Period Page. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2020-36861. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic was found in Nagios Fusion up to 4.1.4. The impacted element is an unknown function. Such manipulation of the argument fusionwindow leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2018-25119. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability identified as problematic has been detected in Nagios Fusion up to 4.0.0. Impacted is an unknown function of the component Users/Servers Page. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2017-20209. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
Conduent Gets Sued; US Government's Cyber Shutdown Woes; Hacktivist Hits Rise The latest ISMG Editors' Panel tackles: post-hack legal fallout for Conduent after it suffered the year's biggest health data breach, the U.S. government's shutdown complicating its response to the breach of vendor F5 and the rise in attacks targeting Western critical national infrastructure.
Nation-State Actor Suspected in Breach of Congressional Budget Office The Congressional Budget Office has been the subject of an apparent cyber incident, officials confirmed Friday, raising concerns that adversaries may have gained access to sensitive data used to inform U.S. legislative decisions amid ongoing federal cyber staffing shortages.
OT Security 'a Generation Behind Traditional IT' For those charged with the cyber defense of OT and industrial control systems, one challenge towers above all others: Data. Specifically, its scarcity. Most operators simply don't capture it, in stark contrast with their IT counterparts.
Senate HELP Committee Chair Seeks to Secure Data in Smart Watches, Health Apps Sen. Bill Cassidy, R-La., a physician and chair of the Senate health committee, has proposed legislation that aims to create parallel HIPAA-like privacy protections to more types of health data - such as data collected by consumer wearable devices and health apps - not currently covered under HIPAA.
A vulnerability has been found in Azure Access BLU-IC2 and BLU-IC4 up to 1.19.5 and classified as critical. Impacted is an unknown function. This manipulation causes missing authentication.
This vulnerability is registered as CVE-2025-12476. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Azure Access BLU-IC2 and BLU-IC4 up to 1.19.5 and classified as critical. The affected element is an unknown function. Such manipulation leads to missing authentication.
This vulnerability is documented as CVE-2025-12477. The attack can be executed remotely. There is not any exploit available.
A vulnerability categorized as problematic has been discovered in Azure Access BLU-IC2 and BLU-IC4 up to 1.19.5. Affected is an unknown function of the component TLS Configuration Handler. The manipulation results in inadequate encryption strength.
This vulnerability is known as CVE-2025-12478. It is possible to launch the attack remotely. No exploit is available.
A vulnerability labeled as problematic has been found in Azure Access BLU-IC2 and BLU-IC4 up to 1.19.5. Affected by this issue is some unknown functionality. Such manipulation leads to cross-site request forgery.
This vulnerability is uniquely identified as CVE-2025-12479. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as problematic, has been found in Zoho ManageEngine Exchange Reporter Plus up to 5721. Affected by this vulnerability is an unknown functionality of the component Search Module. This manipulation causes inefficient regular expression complexity.
This vulnerability appears as CVE-2025-5342. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as problematic, was found in Zoho ManageEngine Exchange Reporter Plus up to 5721. Affected by this issue is some unknown functionality of the component Instant Search Option. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-5343. The attack may be launched remotely. There is no exploit available.