nagios

301 tracked vulnerabilities.

CVE-2026-2043 HIGH
Nagios Host - Command Injection RCE
Feb 20, 2026
CVSS 8.8
EPSS 0.01
CVE-2026-2042 HIGH
Nagios Host - Command Injection RCE
Feb 20, 2026
CVSS 8.8
EPSS 0.02
CVE-2026-2041 HIGH
Nagios Host - Command Injection RCE
Feb 20, 2026
CVSS 8.8
EPSS 0.02
CVE-2025-67255 HIGH
Nagios XI 2026R1.0.1 - Authenticated SQL Injection via Dashboard Parameters
Dec 29, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-67254 HIGH
Nagios XI 2026R1.0.1 - Path Traversal via coreconfigsnapshots.php
Dec 29, 2025
CVSS 7.5
EPSS 0.05
CVE-2025-34288 MEDIUM
Nagios XI < 2026R1.1 - Local Privilege Escalation via Sudo and Writable PHP Include
Dec 16, 2025
CVSS 6.7
EPSS 0.00
CVE-2025-34323 HIGH
Nagios Log Server < 2026R1.0.1 - Local Privilege Escalation via Sudo Misconfiguration and Group-Writable Scripts
Nov 17, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-34322 HIGH
Nagios Log Server < 2026R1.0.1 - Authenticated OS Command Injection via Natural Language Queries
Nov 17, 2025
CVSS 7.2
EPSS 0.00
CVE-2025-34298 HIGH
Nagios Log Server < 2024R1.3.2 - Privilege Escalation via Email Change Workflow
Oct 30, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-34287 HIGH
Nagios XI < 2024R2 - Local Privilege Escalation via Improperly Owned process_perfdata.pl Script
Oct 30, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-34286 HIGH
Nagios XI < 2026R1 - Authenticated Remote Code Execution via Core Config Manager Run Check Command
Oct 30, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-34284 HIGH
Nagios XI < 2024R2 - Authenticated OS Command Injection via WinRM Plugin
Oct 30, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-34283 MEDIUM
Nagios XI <2024R1.4.2 - Info Disclosure
Oct 30, 2025
CVSS 6.5
EPSS 0.01
CVE-2025-34280 HIGH
Nagios Network Analyzer < 2024R2.0.1 - Authenticated Remote Code Execution via LDAP Certificate Removal
Oct 30, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-34278 MEDIUM
Nagios Network Analyzer < 2024 - Stored Cross-Site Scripting in Source Groups Percentile Calculator Menu
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2025-34277 CRITICAL
Nagios Log Server < 2024R1.3.1 - Remote Code Execution via Malformed Dashboard ID
Oct 30, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-34274 CRITICAL
Nagios Log Server <2024R2.0.3 - Privilege Escalation
Oct 30, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-34273 MEDIUM
Nagios Log Server < 2024R2.0.3 - Incorrect Authorization for Global Dashboard Deletion
Oct 30, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34272 MEDIUM
Nagios Log Server < 2024R2.0.3 - Unauthorized Information Exposure via Default Dashboard Fallback
Oct 30, 2025
CVSS 6.5
EPSS 0.01
CVE-2025-34271 CRITICAL
Nagios Log Server < 2024R2.0.2 - Cleartext Transmission of Sensitive Credentials via Cluster Manager
Oct 30, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-34270 MEDIUM
Nagios Log Server < 2024R2.0.2 - Insufficiently Protected Credentials in AD/LDAP User Import
Oct 30, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-34135 MEDIUM
Nagios XI < 2024R1.4.2 - Overly Permissive Systemd Unit File Permissions
Oct 30, 2025
CVSS 4.4
EPSS 0.00
CVE-2025-34134 HIGH
Nagios XI < 2024R1.4.2 - Authenticated Remote Code Execution via BPI Configuration Parameters
Oct 30, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-60425 HIGH
Nagios Fusion <2024R2 - Session Hijacking
Oct 27, 2025
CVSS 8.6
EPSS 0.02
CVE-2025-60424 HIGH
Nagios Fusion <2024R2 - Auth Bypass
Oct 27, 2025
CVSS 7.6
EPSS 0.00