Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Nagios — Vulnerabilities & Security Advisories 117

Browse all 117 CVE security advisories affecting Nagios. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nagios serves as a critical IT infrastructure monitoring solution, enabling organizations to track system health, network performance, and service availability. Historically, its widespread deployment has made it a frequent target for attackers exploiting legacy codebases. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation in web interfaces or CGI scripts. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative control. While the core monitoring engine is generally robust, the associated web frontends and plugins have introduced significant attack surfaces. Major incidents have highlighted the risks of unpatched installations, particularly in environments where default credentials remain active. With over 117 recorded CVEs, the software underscores the necessity for rigorous patch management and strict access controls to mitigate exploitation risks in enterprise security architectures.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2041 Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability — HostCWE-78 8.8AIHighAI2026-02-20
CVE-2026-2043 Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability — HostCWE-78 8.8AIHighAI2026-02-20
CVE-2026-2042 Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability — HostCWE-78 8.8AIHighAI2026-02-20
CVE-2025-34323 Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules — Log ServerCWE-732 7.8AIHighAI2025-11-17
CVE-2025-34322 Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries — Log ServerCWE-78 8.8AIHighAI2025-11-17
CVE-2021-47698 Nagios XI < 5.8.7 XSS in Core UI Views URL handling — XICWE-79 6.1AIMediumAI2025-11-03
CVE-2024-13997 Nagios XI < 2024R1.1.3 Privilege Escalation via Migrate Server Feature to Root on Host — XICWE-269 7.2AIHighAI2025-11-03
CVE-2024-13998 Nagios XI < 2024R1.1.3 API Keys & Hashed Passwords Authenticated Information Disclosure — XICWE-497 8.8AIHighAI2025-11-03
CVE-2024-13992 Nagios XI < 2024R1.1 XSS via Missing Page / 404 — XICWE-79 6.1 -2025-10-31
CVE-2011-10037 Nagios XI < 2011R1.9 XSS via xiwindow Variables Affecting Permalinks — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2021-47697 Nagios XI < 5.8.0 XSS via Views URL Handling — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2018-25121 Nagios XI < 5.4.13 XSS via Views Page — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2013-10074 Nagios XI < 2012R2.6 XSS via Tools Menu — XICWE-79 4.8AIMediumAI2025-10-30
CVE-2011-10040 Nagios XI < 2011R1.9 XSS via Status/Report Page Link Functions — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2016-15051 Nagios XI < 5.2.4 XSS via Report startdate/enddate Fields — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2011-10038 Nagios XI < 2011R1.9 XSS via Recurring Downtime Script — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2021-47695 Nagios XI < 5.8.0 XSS via My Tools Page — XICWE-79 4.8AIMediumAI2025-10-30
CVE-2016-15053 Nagios XI < 5.2.4 XSS via “My Reports” Listing — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2016-15052 Nagios XI < 5.2.4 XSS via Menu System — XICWE-79 4.8AIMediumAI2025-10-30
CVE-2020-36866 Nagios XI < 5.7.3 XSS via Manage Users in Admin Interface — XICWE-79 4.8AIMediumAI2025-10-30
CVE-2023-7316 Nagios XI < 2024R1 XSS via Graph Explorer — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2023-7315 Nagios XI < 5.11.3 XSS via Graph Explorer — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2024-14001 Nagios XI < 2024R1.1.3 XSS via Executive Summary Report — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2020-36864 Nagios XI < 5.7.2 XSS via Dashboard Background Color Setting — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2023-7318 Nagios XI < 2024R1.0.2 XSS via Core Command Expansion — XICWE-79 6.1AIMediumAI2025-10-30
CVE-2024-14000 Nagios XI < 2024R1.1.3 XSS via Capacity Planning Report — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2023-7313 Nagios XI < 5.11.3 XSS via Bulk Modifications — XICWE-79 4.8AIMediumAI2025-10-30
CVE-2020-36865 Nagios XI < 5.7.2 XSS via BPI Config Management — XICWE-79 5.4AIMediumAI2025-10-30
CVE-2021-47696 Nagios XI < 5.8.0 XSS via BPI Config ID Handling — XICWE-79 4.8AIMediumAI2025-10-30
CVE-2023-7314 Nagios XI < 5.11.3 XSS via Bandwidth Report — XICWE-79 6.1AIMediumAI2025-10-30

This page lists every published CVE security advisory associated with Nagios. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.