CVE-2025-34323
- EPSS 0.01%
- Veröffentlicht 17.11.2025 17:48:28
- Zuletzt bearbeitet 26.11.2025 15:15:52
Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has wri...
CVE-2025-34322
- EPSS 0.44%
- Veröffentlicht 17.11.2025 17:48:04
- Zuletzt bearbeitet 26.11.2025 15:15:51
Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selectio...
CVE-2023-7321
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:27:23
- Zuletzt bearbeitet 05.11.2025 18:21:01
Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script i...
CVE-2023-7323
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:27:03
- Zuletzt bearbeitet 06.11.2025 16:20:27
Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the conte...
CVE-2020-36858
- EPSS 0.43%
- Veröffentlicht 30.10.2025 21:26:38
- Zuletzt bearbeitet 05.11.2025 18:25:04
Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an att...
CVE-2024-58272
- EPSS 0.13%
- Veröffentlicht 30.10.2025 21:26:13
- Zuletzt bearbeitet 10.11.2025 19:15:45
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2023-7323.
CVE-2025-34298
- EPSS 0.07%
- Veröffentlicht 30.10.2025 21:25:52
- Zuletzt bearbeitet 06.11.2025 16:27:12
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied t...
CVE-2025-34277
- EPSS 0.21%
- Veröffentlicht 30.10.2025 21:25:32
- Zuletzt bearbeitet 06.11.2025 16:27:31
Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can...
CVE-2025-34272
- EPSS 0.95%
- Veröffentlicht 30.10.2025 21:25:10
- Zuletzt bearbeitet 06.11.2025 16:29:24
In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard b...
CVE-2025-34273
- EPSS 0.19%
- Veröffentlicht 30.10.2025 21:24:43
- Zuletzt bearbeitet 06.11.2025 16:28:38
Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard d...