Log Server
Nagios- Product type
- Other
- Catalog vulnerabilities
- 17
Severity across 17 analyzed records
Verify to analyze this security profile
en
As of 09/14/2026, within CyStack's analyzed data, Log Server has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Log Server and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2025-34323Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules | Exploitation statusPublic exploit | FixYes | Published11/17/2025 | SeverityHigh |
CVE-2025-34322Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries | Exploitation statusPublic exploit | FixYes | Published11/17/2025 | SeverityHigh |
CVE-2023-7321Nagios Log Server < 2.1.14 XSS via Snapshots Page | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityMedium |
CVE-2023-7323Nagios Log Server < 2024R1 XSS via Create User Function | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityMedium |
CVE-2020-36858Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityMedium |
CVE-2025-34298Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityHigh |
CVE-2025-34277Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityCritical |
CVE-2025-34272Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityMedium |
CVE-2025-34273Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityHigh |
CVE-2024-58273Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityHigh |
CVE-2025-34274Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityCritical |
CVE-2023-7322Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityHigh |
CVE-2016-15049Nagios Log Server < 1.4.2 Dashboards Logs Table XSS | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityMedium |
CVE-2025-34271Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityHigh |
CVE-2025-34270Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated | Exploitation statusNot known exploited | FixYes | Published10/30/2025 | SeverityMedium |
CVE-2025-44823 | Exploitation statusPublic exploit | FixYes | Published10/07/2025 | SeverityCritical |
CVE-2025-44824 | Exploitation statusPublic exploit | FixYes | Published10/07/2025 | SeverityHigh |