nagios has 11 CVEs on record between 2021 and 2026. 2 were published in the last 90 days. The median CVSS is 6.5 (medium). 27% have been exploited in the wild — well above the 1% corpus average, so nagios flaws are worth patching on sight. The median gap from publication to a KEV listing is 337 days (3 cases). The most common weakness class is CWE-79 (3). Most affected products: nagios_xi (9), Nagios XI (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 27% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- 337 d median(3)
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2021-25298High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection88CVE-2021-25296High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection88CVE-2021-25297High· 8.8Nagios XI version xi-5.7.5 is affected by OS command injection85CVE-2021-25299Medium· 6.1Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)65CVE-2024-33775High· 8.8An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.61
nagios vulnerabilities
CVEs affecting nagios, newest first. Open any entry for full detail, references, and exploit status.
11 CVEsRSS
CVE-2023-24035Low· 3.5An issue was discovered in Nagios XI before 5.9.3
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in t…
CVE-2023-24034Low· 3.1An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3
An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.
CVE-2023-7314Medium· 5.4Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script i…
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script i…
CVE-2023-7313Medium· 5.4Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool
Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bulk Modifications tool. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in t…
CVE-2024-33775High· 8.8PoCAn issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.
CVE-2021-37223Medium· 6.5Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php
Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. Any authenticated user can create scheduled reports containing PDF screenshots of any view in the NagiosXI applicatio…
CVE-2021-37345High· 7.8Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the var directory for some scripts with elevated permissions.
CVE-2021-25298High· 8.8CISA KEVPoCNagios XI version xi-5.7.5 is affected by OS command injection
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled …
CVE-2021-25297High· 8.8CISA KEVPoCNagios XI version xi-5.7.5 is affected by OS command injection
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled inpu…
CVE-2021-25296High· 8.8CISA KEVPoCNagios XI version xi-5.7.5 is affected by OS command injection
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-control…
CVE-2021-25299Medium· 6.1PoCNagios XI version xi-5.7.5 is affected by cross-site scripting (XSS)
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when …