5.1

CVSS4.0

CVE-2023-7319 - Nagios Network Analyzer < 2024R1 XSS via Percentile Calculator Menu

Nagios Network Analyzer versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Percentile Calculator menu. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:28 p.m. 🔄 Last Modified: Nov. 7, 2025, 7:15 p.m.

5.1

CVSS4.0

CVE-2025-34278 - Nagios Network Analyzer < 2024R1 Source Groups / Percentile Calculator Menu Stored XSS

Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source Groups page (percentile calculator menu). An attacker can supply a malicious payload which is stored by the application and later rendered in the context of other users. When a v…

📅 Published: Oct. 30, 2025, 9:28 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:15 p.m.

8.6

CVSS4.0

CVE-2025-34280 - Nagios Network Analyzer < 2024R2.0.1 RCE in LDAP Certificate Removal Function

Nagios Network Analyzer versions prior to 2024R2.0.1 contain a vulnerability in the LDAP certificate management functionality whereby the certificate removal operation fails to apply adequate input sanitation. An authenticated administrator can trigger command execution on the underlying host in th…

📅 Published: Oct. 30, 2025, 9:27 p.m. 🔄 Last Modified: Nov. 6, 2025, 6:15 p.m.

5.1

CVSS4.0

CVE-2023-7321 - Nagios Log Server < 2.1.14 XSS via Snapshots Page

Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in the victim’s browser within the application ori…

📅 Published: Oct. 30, 2025, 9:27 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:21 p.m.

5.1

CVSS4.0

CVE-2023-7323 - Nagios Log Server < 2024R1 XSS via Create User Function

Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:27 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2020-36858 - Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in t…

📅 Published: Oct. 30, 2025, 9:26 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:25 p.m.

0.0

CVE-2024-58272 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2023-7323.

📅 Published: Oct. 30, 2025, 9:26 p.m. 🔄 Last Modified: Nov. 10, 2025, 7:15 p.m.

8.7

CVSS4.0

CVE-2025-34298 - Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent acco…

📅 Published: Oct. 30, 2025, 9:25 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:27 p.m.

9.4

CVSS4.0

CVE-2025-34277 - Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to execute attacker-controlled …

📅 Published: Oct. 30, 2025, 9:25 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:27 p.m.

5.3

CVSS4.0

CVE-2025-34272 - Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depend…

📅 Published: Oct. 30, 2025, 9:25 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:29 p.m.
Total resulsts: 318411
Page 205 of 31,842
« previous page » next page
Filters