Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Nagios — Vulnerabilities & Security Advisories 117

Browse all 117 CVE security advisories affecting Nagios. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nagios serves as a critical IT infrastructure monitoring solution, enabling organizations to track system health, network performance, and service availability. Historically, its widespread deployment has made it a frequent target for attackers exploiting legacy codebases. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation in web interfaces or CGI scripts. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative control. While the core monitoring engine is generally robust, the associated web frontends and plugins have introduced significant attack surfaces. Major incidents have highlighted the risks of unpatched installations, particularly in environments where default credentials remain active. With over 117 recorded CVEs, the software underscores the necessity for rigorous patch management and strict access controls to mitigate exploitation risks in enterprise security architectures.

Found 17 results / 117Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-34323 Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules — Log ServerCWE-732 7.8AIHighAI2025-11-17
CVE-2025-34322 Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries — Log ServerCWE-78 8.8AIHighAI2025-11-17
CVE-2023-7321 Nagios Log Server < 2.1.14 XSS via Snapshots Page — Log ServerCWE-79 6.1AIMediumAI2025-10-30
CVE-2023-7323 Nagios Log Server < 2024R1 XSS via Create User Function — Log ServerCWE-79 5.4AIMediumAI2025-10-30
CVE-2020-36858 Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages — Log ServerCWE-79 4.8AIMediumAI2025-10-30
CVE-2025-34298 Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation — Log ServerCWE-281 8.8AIHighAI2025-10-30
CVE-2025-34277 Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID — Log ServerCWE-94 9.8AICriticalAI2025-10-30
CVE-2025-34272 Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback — Log ServerCWE-200 9.1AICriticalAI2025-10-30
CVE-2025-34273 Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion — Log ServerCWE-863 4.3AIMediumAI2025-10-30
CVE-2024-58273 Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root — Log ServerCWE-266 7.8AIHighAI2025-10-30
CVE-2025-34274 Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges — Log ServerCWE-250 8.8AIHighAI2025-10-30
CVE-2023-7322 Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access — Log ServerCWE-863 8.1AIHighAI2025-10-30
CVE-2016-15049 Nagios Log Server < 1.4.2 Dashboards Logs Table XSS — Log ServerCWE-79 6.1AIMediumAI2025-10-30
CVE-2025-34271 Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext — Log ServerCWE-319 8.8AIHighAI2025-10-30
CVE-2025-34270 Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated — Log ServerCWE-312 8.8AIHighAI2025-10-30
CVE-2025-44823 Nagios Log Server 安全漏洞 — Log ServerCWE-497 9.9 Critical2025-10-07
CVE-2025-44824 Nagios Log Server 安全漏洞 — Log ServerCWE-863 8.5 High2025-10-07

This page lists every published CVE security advisory associated with Nagios. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.