CVE Database

114379+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-34287
7.8 HIGH

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because …

Oct 30, 2025
CVE-2025-34286
7.2 HIGH

Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core Config Manager (CCM) Run Check command. Insufficient validation/escaping of parameters …

Oct 30, 2025
CVE-2025-34284
8.8 HIGH

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to …

Oct 30, 2025
CVE-2025-34283
6.5 MEDIUM

Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user …

Oct 30, 2025
CVE-2025-34280
7.2 HIGH

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate …

Oct 30, 2025
CVE-2025-34278
5.4 MEDIUM

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can …

Oct 30, 2025
CVE-2025-34277
9.8 CRITICAL

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to …

Oct 30, 2025
CVE-2025-34274
9.8 CRITICAL

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. …

Oct 30, 2025
CVE-2025-34273
6.5 MEDIUM

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly …

Oct 30, 2025
CVE-2025-34272
6.5 MEDIUM

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an …

Oct 30, 2025
CVE-2025-34271
9.8 CRITICAL

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted …

Oct 30, 2025
CVE-2025-34270
4.9 MEDIUM

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during …

Oct 30, 2025
CVE-2025-34269

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60424.

Oct 30, 2025
CVE-2025-34249

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2025-60425.

Oct 30, 2025
CVE-2025-34135
4.4 MEDIUM

Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. In particular, the nagios.service unit had executable …

Oct 30, 2025
CVE-2025-34134
7.2 HIGH

Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the Business Process Intelligence (BPI) component. Insufficient validation and sanitization of administrator-controlled …

Oct 30, 2025
CVE-2024-58273
7.8 HIGH

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web …

Oct 30, 2025
CVE-2024-58272

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2023-7323.

Oct 30, 2025
CVE-2024-14009
7.2 HIGH

Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System Profile component. The System Profile feature is an administrative diagnostic/configuration capability. …

Oct 30, 2025
CVE-2024-14008
7.2 HIGH

Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated …

Oct 30, 2025
CVE-2024-14006
6.1 MEDIUM

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without …

Oct 30, 2025
CVE-2024-14005
8.8 HIGH

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an …

Oct 30, 2025
CVE-2024-14004
8.8 HIGH

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data …

Oct 30, 2025
CVE-2024-14003
9.8 CRITICAL

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of …

Oct 30, 2025
CVE-2024-14002
5.5 MEDIUM

Nagios XI versions prior to 2024R1.1.4 contain a local file inclusion (LFI) vulnerability via its NagVis integration. An authenticated user can supply crafted path values …

Oct 30, 2025
CVE-2024-14001
5.4 MEDIUM

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Executive Summary Report component. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2024-14000
5.4 MEDIUM

Nagios XI versions prior to 2024R1.1.3 are vulnerable to cross-site scripting (XSS) via the Capacity Planning Report component. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2024-13999
9.8 CRITICAL

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of …

Oct 30, 2025
CVE-2024-13996
9.8 CRITICAL

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, …

Oct 30, 2025
CVE-2024-13995
8.8 HIGH

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated …

Oct 30, 2025
CVE-2024-13994
9.8 CRITICAL

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can …

Oct 30, 2025
CVE-2024-13993
6.1 MEDIUM

Nagios XI versions prior to < 2024R1.1.2 are vulnerable to a reflected cross-site scripting (XSS) via the login page when accessed with older web browsers. …

Oct 30, 2025
CVE-2023-7325

Anheng Mingyu Operation and Maintenance Audit and Risk Control System up to 2023-08-10 contains a server-side request forgery (SSRF) vulnerability in the xmlrpc.sock handler. The …

Oct 30, 2025
CVE-2023-7323
5.4 MEDIUM

Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2023-7322
8.1 HIGH

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API …

Oct 30, 2025
CVE-2023-7321
5.4 MEDIUM

Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for …

Oct 30, 2025
CVE-2023-7319
5.4 MEDIUM

Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2023-7318
5.4 MEDIUM

Nagios XI versions prior to < 2024R1.0.2 are vulnerable to cross-site scripting (XSS) via the Nagios Core Command Expansion page. Insufficient validation or escaping of …

Oct 30, 2025
CVE-2023-7317
8.8 HIGH

Nagios XI versions prior to 2024R1 contain a missing access control vulnerability via the Web SSH Terminal. A remote, low-privileged attacker could access or interact …

Oct 30, 2025
CVE-2023-7316
5.4 MEDIUM

Nagios XI versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7315
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Graph Explorer component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7314
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7313
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2023-7312
4.8 MEDIUM

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability when adding or configuring Email Settings. Unsanitized user input can be stored …

Oct 30, 2025
CVE-2023-53690
4.8 MEDIUM

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and …

Oct 30, 2025
CVE-2023-53689
4.8 MEDIUM

Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the license key configuration flow that can result in execution of …

Oct 30, 2025
CVE-2023-53688
5.4 MEDIUM

Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) and cross-site request forgery (CSRF) via the Hypermap Replay component. An attacker can …

Oct 30, 2025
CVE-2022-50588
5.4 MEDIUM

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the update checking feature. Insufficient validation or escaping of user-supplied input may …

Oct 30, 2025
CVE-2022-50587
5.4 MEDIUM

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) via the Apply Configuration error text. Insufficient validation or escaping of user-supplied input …

Oct 30, 2025
CVE-2022-50586
5.4 MEDIUM

Nagios XI versions prior to 5.8.9 are vulnerable to cross-site scripting (XSS) in the BPI component via the info URL field. Insufficient validation or escaping …

Oct 30, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.