8.7

CVSS4.0

CVE-2025-34298 - Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent acco…

📅 Published: Oct. 30, 2025, 9:25 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:27 p.m.

9.4

CVSS4.0

CVE-2025-34277 - Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to execute attacker-controlled …

📅 Published: Oct. 30, 2025, 9:25 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:27 p.m.

5.3

CVSS4.0

CVE-2025-34272 - Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depend…

📅 Published: Oct. 30, 2025, 9:25 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:29 p.m.

7.1

CVSS4.0

CVE-2025-34273 - Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard deletion workflow, enabling lower-privileged users…

📅 Published: Oct. 30, 2025, 9:24 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:28 p.m.

8.5

CVSS4.0

CVE-2024-58273 - Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host.

📅 Published: Oct. 30, 2025, 9:24 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:34 p.m.

9.3

CVSS4.0

CVE-2025-34274 - Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin, pipeline configuration i…

📅 Published: Oct. 30, 2025, 9:23 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:27 p.m.

8.7

CVSS4.0

CVE-2023-7322 - Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could …

📅 Published: Oct. 30, 2025, 9:23 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:20 p.m.

5.1

CVSS4.0

CVE-2016-15049 - Nagios Log Server < 1.4.2 Dashboards Logs Table XSS

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in …

📅 Published: Oct. 30, 2025, 9:23 p.m. 🔄 Last Modified: Nov. 5, 2025, 6:27 p.m.

8.7

CVSS4.0

CVE-2025-34271 - Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network pat…

📅 Published: Oct. 30, 2025, 9:22 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:29 p.m.

6.9

CVSS4.0

CVE-2025-34270 - Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnost…

📅 Published: Oct. 30, 2025, 9:22 p.m. 🔄 Last Modified: Nov. 6, 2025, 4:31 p.m.
Total resulsts: 318414
Page 206 of 31,842
« previous page » next page
Filters