8.5

CVSS4.0

CVE-2024-58273 - Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root

Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root on the host.

📅 Published: Oct. 30, 2025, 9:24 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

9.3

CVSS4.0

CVE-2025-34274 - Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges

Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin, pipeline configuration i…

📅 Published: Oct. 30, 2025, 9:23 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

8.7

CVSS4.0

CVE-2023-7322 - Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could …

📅 Published: Oct. 30, 2025, 9:23 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

5.1

CVSS4.0

CVE-2016-15049 - Nagios Log Server < 1.4.2 Dashboards Logs Table XSS

Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script in …

📅 Published: Oct. 30, 2025, 9:23 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

8.7

CVSS4.0

CVE-2025-34271 - Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in the product configuration. As a result, an attacker positioned on the network pat…

📅 Published: Oct. 30, 2025, 9:22 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

6.9

CVSS4.0

CVE-2025-34270 - Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnost…

📅 Published: Oct. 30, 2025, 9:22 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

5.1

CVSS4.0

CVE-2017-20209 - Nagios Fusion < 4.0.1 XSS via Users/Servers Page

Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:22 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

5.1

CVSS4.0

CVE-2018-25119 - Nagios Fusion < 4.1.5 XSS via fusionwindow Parameter

Nagios Fusion versions prior to 4.1.5 are vulnerable to cross-site scripting (XSS) via the "fusionwindow" parameter. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.

📅 Published: Oct. 30, 2025, 9:21 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

6

CVSS4.0

CVE-2023-53689 - Nagios Fusion < 4.2.0 License Information Reflected XSS

Nagios Fusion versions prior to 4.2.0 contain a reflected cross-site scripting (XSS) vulnerability in the license key configuration flow that can result in execution of attacker-controlled script in the browser of a user who follows a crafted URL. While the application server itself is not directly…

📅 Published: Oct. 30, 2025, 9:20 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.

6.2

CVSS4.0

CVE-2023-53690 - Nagios Fusion < 4.2.0 LDAP/AD Integration Stored XSS

Nagios Fusion versions prior to 4.2.0 contain a stored cross-site scripting (XSS) vulnerability in the LDAP/AD authentication-server configuration. Unsanitized user input can be stored and later rendered in the administrative UI, causing JavaScript to execute in the browser of any user who views th…

📅 Published: Oct. 30, 2025, 9:20 p.m. 🔄 Last Modified: Nov. 17, 2025, 9:36 p.m.
Total resulsts: 349182
Page 3207 of 34,919
« previous page » next page
Filters