Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Log Server — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Log Server, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting the Log Server product, focusing on common weakness classifications and associated risk tags. It aggregates known security flaws discovered within this software ecosystem, covering a historical timeframe from initial public disclosures up to the most recent patches and advisory releases. By reviewing this centralized resource, users can effectively track vendor advisories as they evolve, gain a deeper understanding of specific weakness classes and their potential impact on system integrity, and examine the complete vulnerability history of the Log Server to assess long-term exposure and mitigation strategies. The content is curated to provide a clear, chronological view of security incidents, allowing administrators and security analysts to identify recurring patterns, prioritize remediation efforts, and compare threat landscapes across different versions. This approach supports informed decision-making by presenting raw data on exploit availability, severity ratings, and vendor response times without unnecessary embellishment. The goal is to offer a transparent and comprehensive reference that enables stakeholders to evaluate the security posture of their logging infrastructure accurately. All listed items are sourced from official vendor announcements, independent security research, and established vulnerability databases to ensure accuracy and relevance. This aggregation serves as a practical tool for maintaining compliance, enhancing monitoring capabilities, and reducing the window of exposure to known exploits.

Vendor: Nagios

CVE ID Title CVSS Severity Published
CVE-2025-34323 Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules CWE-732 7.8AI High AI 2025-11-17
CVE-2025-34322 Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries CWE-78 8.8AI High AI 2025-11-17
CVE-2023-7321 Nagios Log Server < 2.1.14 XSS via Snapshots Page CWE-79 6.1AI Medium AI 2025-10-30
CVE-2023-7323 Nagios Log Server < 2024R1 XSS via Create User Function CWE-79 5.4AI Medium AI 2025-10-30
CVE-2020-36858 Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages CWE-79 4.8AI Medium AI 2025-10-30
CVE-2025-34298 Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation CWE-281 8.8AI High AI 2025-10-30
CVE-2025-34277 Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID CWE-94 9.8AI Critical AI 2025-10-30
CVE-2025-34272 Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback CWE-200 9.1AI Critical AI 2025-10-30
CVE-2025-34273 Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion CWE-863 4.3AI Medium AI 2025-10-30
CVE-2024-58273 Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root CWE-266 7.8AI High AI 2025-10-30
CVE-2025-34274 Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges CWE-250 8.8AI High AI 2025-10-30
CVE-2023-7322 Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access CWE-863 8.1AI High AI 2025-10-30
CVE-2016-15049 Nagios Log Server < 1.4.2 Dashboards Logs Table XSS CWE-79 6.1AI Medium AI 2025-10-30
CVE-2025-34271 Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext CWE-319 8.8AI High AI 2025-10-30
CVE-2025-34270 Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated CWE-312 8.8AI High AI 2025-10-30
CVE-2025-44823 Nagios Log Server 安全漏洞 CWE-497 9.9 Critical 2025-10-07
CVE-2025-44824 Nagios Log Server 安全漏洞 CWE-863 8.5 High 2025-10-07

All 17 known CVE vulnerabilities affecting Log Server with full Chinese analysis, references, and POCs where available.