Known Vulnerabilities for products from Nagios
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Nagios".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73974 json | Not Provided | 2026-08-18 | 2026-08-19 | |
| CVE-2026-73973 json | Not Provided | 2026-08-18 | 2026-08-19 | |
| CVE-2026-67436 json | Not Provided | 2026-07-29 | 2026-07-30 | |
| CVE-2026-67433 json | Not Provided | 2026-07-29 | 2026-07-30 | |
| CVE-2026-55426 json | Not Provided | 2026-08-18 | 2026-08-20 | |
| CVE-2026-52817 json | Not Provided | 2026-08-18 | 2026-08-19 | |
| CVE-2026-48554 json | Not Provided | 2026-08-12 | 2026-08-14 | |
| CVE-2026-48553 json | Not Provided | 2026-08-12 | 2026-08-14 | |
| CVE-2026-48552 json | Not Provided | 2026-08-12 | 2026-08-14 | |
| CVE-2026-48551 json | Not Provided | 2026-08-12 | 2026-08-14 | |
| CVE-2025-56432 json | A cross-site scripting (XSS) vulnerability exists in Nagios XI 2024R2. The vulnerability allows remote attackers to execute a... | Not Provided | 2025-08-26 | 2026-07-05 |
| CVE-2024-33775 json | An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted... | Not Provided | 2024-05-01 | 2026-08-24 |
| CVE-2024-13998 json | Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose sensitive user account information (including ... | Not Provided | 2025-11-03 | 2026-09-26 |
| CVE-2024-13997 json | Nagios XI versions prior to 2024R1.1.3 contain a privilege escalation vulnerability in which an authenticated administrato... | Not Provided | 2025-11-03 | 2026-09-26 |
| CVE-2024-13986 json | Nagios XI < 2024R1.3.2 contains a remote code execution vulnerability by chaining two flaws: an arbitrary file upload and a p... | Not Provided | 2025-08-28 | 2026-09-26 |
| CVE-2023-40934 json | A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host esc... | Not Provided | 2023-09-19 | 2026-07-09 |
| CVE-2023-40933 json | A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configur... | Not Provided | 2023-09-19 | 2026-07-09 |
| CVE-2023-40932 json | A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access t... | Not Provided | 2023-09-19 | 2026-07-09 |
| CVE-2023-40931 json | A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to e... | Not Provided | 2023-09-19 | 2026-07-09 |
| CVE-2023-7314 json | Nagios XI versions prior to 5.11.3 are vulnerable to cross-site scripting (XSS) via the Bandwidth Report component. Insuffi... | Not Provided | 2025-10-30 | 2026-09-03 |
Known software with vulnerabilities from Nagios
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Nagios | Business Process Intelligence | 2.3.4 |
| Application | Nagios | Favorites | - |
| Application | Nagios | Fusion | 4.0.0 |
| Application | Nagios | Incident Manager | 2.0.0 |
| Application | Nagios | Log Server | - |
| Application | Nagios | Nagios | 2.0.1 |
| Application | Nagios | Nagios Core | 1.0.0 |
| Application | Nagios | Nagios Xi | 2009 |
| Application | Nagios | Plugins | 1.3.0 |
| Application | Nagios | Remote Plugin Executor | 2.15 |
| Application | Nagios | Remote Plug In Executor | 1.3 |