VendorsNagioslog_server2024
Vulnerabilities

Nagios Log Server 2024

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2025-44823
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.
Published 2025-10-07 · Analyzed
9.9EPSS 0.161
CVE-2025-34277
Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID
Published 2025-10-30 · Analyzed
9.8EPSS 0.020
CVE-2025-34274
Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges
Published 2025-10-30 · Analyzed
9.8EPSS 0.019
CVE-2025-34271
Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext
Published 2025-10-30 · Analyzed
9.8EPSS 0.007
CVE-2025-34298
Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation
Published 2025-10-30 · Analyzed
8.8EPSS 0.007
CVE-2025-44824
Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response. This is GL:NLS#474.
Published 2025-10-07 · Analyzed
8.5EPSS 0.028
CVE-2024-58273
Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root
Published 2025-10-30 · Analyzed
8.5EPSS 0.003
CVE-2025-29471
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
Published 2025-04-15 · Analyzed
8.31 PoCEPSS 0.072
CVE-2025-34273
Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion
Published 2025-10-30 · Analyzed
7.1EPSS 0.010
CVE-2025-34270
Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated
Published 2025-10-30 · Analyzed
6.9EPSS 0.006
CVE-2025-34272
Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback
Published 2025-10-30 · Analyzed
6.5EPSS 0.008