Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Nagios — Vulnerabilities & Security Advisories 119

Browse all 119 CVE security advisories affecting Nagios. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Nagios serves as a critical IT infrastructure monitoring solution, enabling organizations to track system health, network performance, and service availability. Historically, its widespread deployment has made it a frequent target for attackers exploiting legacy codebases. Common vulnerability classes include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL injection, often stemming from insufficient input validation in web interfaces or CGI scripts. Privilege escalation flaws have also been documented, allowing unauthorized users to gain administrative control. While the core monitoring engine is generally robust, the associated web frontends and plugins have introduced significant attack surfaces. Major incidents have highlighted the risks of unpatched installations, particularly in environments where default credentials remain active. With over 117 recorded CVEs, the software underscores the necessity for rigorous patch management and strict access controls to mitigate exploitation risks in enterprise security architectures.

CVE ID Title CVSS Severity Published
CVE-2025-34298 Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation — Log Server CWE-281 8.8AI High AI 2025-10-30
CVE-2025-34277 Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID — Log Server CWE-94 9.8AI Critical AI 2025-10-30
CVE-2025-34272 Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback — Log Server CWE-200 9.1AI Critical AI 2025-10-30
CVE-2025-34273 Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion — Log Server CWE-863 4.3AI Medium AI 2025-10-30
CVE-2024-58273 Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root — Log Server CWE-266 7.8AI High AI 2025-10-30
CVE-2025-34274 Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges — Log Server CWE-250 8.8AI High AI 2025-10-30
CVE-2023-7322 Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access — Log Server CWE-863 8.1AI High AI 2025-10-30
CVE-2016-15049 Nagios Log Server < 1.4.2 Dashboards Logs Table XSS — Log Server CWE-79 6.1AI Medium AI 2025-10-30
CVE-2025-34271 Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext — Log Server CWE-319 8.8AI High AI 2025-10-30
CVE-2025-34270 Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated — Log Server CWE-312 8.8AI High AI 2025-10-30
CVE-2017-20209 Nagios Fusion < 4.0.1 XSS via Users/Servers Page — Fusion CWE-79 5.4AI Medium AI 2025-10-30
CVE-2018-25119 Nagios Fusion < 4.1.5 XSS via fusionwindow Parameter — Fusion CWE-79 6.1AI Medium AI 2025-10-30
CVE-2023-53689 Nagios Fusion < 4.2.0 License Information Reflected XSS — Fusion CWE-79 6.1AI Medium AI 2025-10-30
CVE-2023-53690 Nagios Fusion < 4.2.0 LDAP/AD Integration Stored XSS — Fusion CWE-79 5.4AI Medium AI 2025-10-30
CVE-2023-7312 Nagios Fusion < 4.2.0 Email Settings Stored XSS via SMTP/sendmail — Fusion CWE-79 4.8AI Medium AI 2025-10-30
CVE-2025-44823 Nagios Log Server 安全漏洞 — Log Server CWE-497 9.9 Critical 2025-10-07
CVE-2025-44824 Nagios Log Server 安全漏洞 — Log Server CWE-863 8.5 High 2025-10-07
CVE-2025-34227 Nagios XI < 2026R1 Configuration Wizard Authenticated Command Injection — Nagios XI CWE-78 8.8AI High AI 2025-09-25
CVE-2024-13986 Nagios XI < 2024R1.3.2 Authenticated Arbitrary File Upload Path Traversal RCE — Nagios XI CWE-434 8.8AI High AI 2025-08-28
CVE-2021-4285 Nagios NCPA tail.html cross site scripting — NCPA CWE-79 3.5 Low 2022-12-27
CVE-2021-33179 Nagios XI 跨站脚本漏洞 — Nagios XI CWE-79 5.4 - 2021-10-14
CVE-2021-33177 Nagios XI SQL注入漏洞 — Nagios XI CWE-89 8.8 - 2021-10-14
CVE-2018-15708 Nagios XI Snoopy 命令注入漏洞 — Nagios XI 9.8 - 2018-11-14
CVE-2018-15709 Nagios XI 安全漏洞 — Nagios XI 8.8 - 2018-11-14
CVE-2018-15710 Nagios XI 命令注入漏洞 — Nagios XI 7.8 - 2018-11-14
CVE-2018-15711 Nagios XI 安全漏洞 — Nagios XI 8.8 - 2018-11-14
CVE-2018-15712 Nagios XI 跨站脚本漏洞 — Nagios XI 6.1 - 2018-11-14
CVE-2018-15713 Nagios XI 跨站脚本漏洞 — Nagios XI 5.4 - 2018-11-14
CVE-2018-15714 Nagios XI 跨站脚本漏洞 — Nagios XI 6.1 - 2018-11-14

This page lists every published CVE security advisory associated with Nagios. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.