Nagios
Nagios LOG Server: vulnerabilidades y CVE
Nagios LOG Server tiene 23 vulnerabilidades publicadas, 17 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE23
Últimos 12 meses17
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-34323 | Alta (8.5) | 0.33% | — | 17 nov 2025 | Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of… |
| CVE-2025-34322 | Alta (8.6) | 9.5% | — | 17 nov 2025 | Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled… |
| CVE-2025-34298 | Alta (8.7) | 0.70% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation… |
| CVE-2025-34277 | Crítica (9.4) | 2.2% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply… |
| CVE-2025-34274 | Crítica (9.3) | 2.1% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash… |
| CVE-2025-34273 | Alta (7.1) | 1.0% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization… |
| CVE-2025-34272 | Media (5.3) | 0.86% | — | 30 oct 2025 | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can… |
| CVE-2025-34271 | Alta (8.7) | 0.74% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting sensitive credentials from peer nodes over an unencrypted channel even when SSL/TLS is enabled in… |
| CVE-2025-34270 | Media (6.9) | 0.63% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for… |
| CVE-2023-7323 | Media (5.1) | 0.51% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and… |
| CVE-2023-7322 | Alta (8.7) | 1.1% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to… |
| CVE-2023-7321 | Media (5.1) | 0.51% | — | 30 oct 2025 | Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data… |
| CVE-2020-36858 | Media (5.1) | 0.51% | — | 30 oct 2025 | Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of… |
| CVE-2016-15049 | Media (5.1) | 0.51% | — | 30 oct 2025 | Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when rendering log entries in the Logs table. Untrusted log content was not safely encoded for the output… |
| CVE-2024-58273 | Alta (8.5) | 0.28% | — | 30 oct 2025 | Nagios Log Server versions prior to 2024R1.0.2 contain a local privilege escalation vulnerability that allows an attacker who could execute commands as the Apache web user (or the backend shell user) to escalate to root… |
| CVE-2025-44824 | Media (6.5) | 2.8% | — | 7 oct 2025 | Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service… |
| CVE-2025-44823 | Alta (8.8) | 16% | — | 7 oct 2025 | Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475. |
| CVE-2025-29471 | Alta (8.3) | 7.2% | — | 15 abr 2025 | Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field. |
| CVE-2021-35479 | Media (5.4) | 13% | — | 30 jul 2021 | Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web… |
| CVE-2021-35478 | Media (5.4) | 77% | — | 30 jul 2021 | Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. All parameters used for filtering are affected. This affects users who open a crafted link or… |
| CVE-2020-25385 | Media (6.1) | 16% | — | 20 ene 2021 | Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link… |
| CVE-2020-16157 | Media (5.4) | 14% | — | 30 jul 2020 | A Stored XSS vulnerability exists in Nagios Log Server before 2.1.7 via the Notification Methods -> Email Users menu. |
| CVE-2019-15898 | Media (6.1) | 1.6% | — | 3 sept 2019 | Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page. |