nagios

301 tracked vulnerabilities.

CVE-2025-44824 HIGH
Nagios Log Server < 2024R1.3.2 - Authenticated Denial of Service via Elasticsearch Stop API
Oct 07, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-44823 CRITICAL
Nagios Log Server <2024R1.3.2 - Info Disclosure
Oct 07, 2025
CVSS 9.9
EPSS 0.01
CVE-2025-34227 HIGH
Nagios XI < 2026R1 - Authenticated OS Command Injection via Database Wizard Arguments
Sep 25, 2025
CVSS 8.8
EPSS 0.03
CVE-2025-56432 MEDIUM
Nagios XI 2024R2 - Stored Cross-Site Scripting in Performance Data Renderer
Aug 26, 2025
CVSS 6.1
EPSS 0.01
CVE-2025-28059 HIGH
Nagios Network Analyzer 2024R1.0.3 - Insufficient Session Expiration
Apr 18, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-29471 HIGH
Nagios Log Server 2024R1.3.1 - Cross-Site Scripting via Email Field
Apr 15, 2025
CVSS 8.3
EPSS 0.18
CVE-2025-28132 MEDIUM
Nagios Network Analyzer 2024R1.0.3 - Insufficient Session Expiration
Apr 01, 2025
CVSS 4.6
EPSS 0.00
CVE-2025-28131 MEDIUM
Nagios Network Analyzer 2024R1.0.3 - Broken Access Control
Apr 01, 2025
CVSS 4.6
EPSS 0.00
CVE-2024-13998 MEDIUM
Nagios XI <2024R1.1.3 - Info Disclosure
Nov 03, 2025
CVSS 6.5
EPSS 0.01
CVE-2024-13997 HIGH
Nagios XI < 2024R1.1.3 - Authenticated Privilege Escalation via Migrate Server Feature
Nov 03, 2025
CVSS 7.2
EPSS 0.00
CVE-2024-13992 MEDIUM
Nagios XI < 2024R1.1 - Stored Cross-Site Scripting via Missing Page
Oct 31, 2025
CVSS 5.4
EPSS 0.01
CVE-2024-58273 HIGH
Nagios Log Server < 2024R1.0.2 - Local Privilege Escalation from Apache User to Root
Oct 30, 2025
CVSS 7.8
EPSS 0.00
CVE-2024-14009 HIGH
Nagios XI < 2024R1.0.1 - Authenticated Privilege Escalation via System Profile
Oct 30, 2025
CVSS 7.2
EPSS 0.00
CVE-2024-14008 HIGH
Nagios XI < 2024R1.3.2 - Authenticated Remote Code Execution via WinRM Configuration Wizard
Oct 30, 2025
CVSS 7.2
EPSS 0.01
CVE-2024-14006 MEDIUM
Nagios XI < 2024R1.2.2 - Host Header Injection
Oct 30, 2025
CVSS 6.1
EPSS 0.00
CVE-2024-14005 HIGH
Nagios XI < 2024R1.2 - Authenticated OS Command Injection via Docker Wizard
Oct 30, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-14004 HIGH
Nagios XI < 2024R1.2 - Authenticated Privilege Escalation via NagVis Configuration Handling
Oct 30, 2025
CVSS 8.8
EPSS 0.00
CVE-2024-14003 CRITICAL
Nagios XI < 2024R1.2 - Remote Code Execution via NRDP Server Plugin Parameter Injection
Oct 30, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-14002 MEDIUM
Nagios XI < 2024R1.1.4 - Authenticated Local File Inclusion via NagVis Integration
Oct 30, 2025
CVSS 5.5
EPSS 0.00
CVE-2024-14001 MEDIUM
Nagios XI < 2024R1.1.3 - Cross-Site Scripting via Executive Summary Report
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2024-14000 MEDIUM
Nagios XI < 2024R1.1.3 - Cross-Site Scripting via Capacity Planning Report
Oct 30, 2025
CVSS 5.4
EPSS 0.01
CVE-2024-13999 CRITICAL
Nagios XI <2024R1.1.3 - Info Disclosure
Oct 30, 2025
CVSS 9.8
EPSS 0.01
CVE-2024-13996 CRITICAL
Nagios XI < 2024R1.1.3 - Insufficient Session Expiration
Oct 30, 2025
CVSS 9.8
EPSS 0.00
CVE-2024-13995 HIGH
Nagios XI <2024R1.1.2 - Info Disclosure
Oct 30, 2025
CVSS 8.8
EPSS 0.02
CVE-2024-13994 CRITICAL
Nagios XI < 2024R1.1.2 - Missing Authorization via Insecure Login Option
Oct 30, 2025
CVSS 9.8
EPSS 0.00