Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nagios

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 301
68.7
VTI Score
TOP TARGET

Nagios maintains a suite of monitoring and infrastructure-management products—including Nagios XI, the core Nagios engine, Log Server, Fusion, and Network Analyzer—that sit centrally in observability and control layers across enterprise environments, and its vulnerability footprint is correspondingly large and prominent in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a consistent tendency toward public exploit availability, reflecting the appeal of web-facing monitoring platforms and their command-execution capabilities as high-value targets. The exposure recurs across the product line through web-tier and system-integration weakness classes including cross-site scripting, OS command injection, SQL injection, and improper privilege management, which are endemic to monitoring dashboards and their backend integration with monitored infrastructure. Defenders should treat Nagios advisories as high-priority, particularly for internet-exposed instances, and maintain strict access controls around monitoring platforms; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
301
Total CVEs
More Total CVEs than 100% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
1.3%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Nagios over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Feb 20, 2026
154 days ago

Products(18 total)

Top CVEs

Signals from CVEs in this vendor scope (301 CVEs).

301 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-25298HIGH
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due t
Feb 15, 20218.897YESYES
CVE-2019-15949HIGH
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The
Sep 5, 20198.897YESYES
CVE-2021-25296HIGH
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php d
Feb 15, 20218.896YESYES
CVE-2021-25297HIGH
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to im
Feb 15, 20218.895YESYES
CVE-2018-15708CRITICAL
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nov 14, 20189.890NOYES
CVE-2009-2288HIGH
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.
Jul 1, 20097.584NOYES
CVE-2021-25299MEDIUM
Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization o
Feb 15, 20216.183NOYES
CVE-2020-35578HIGH
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticat
Jan 13, 20217.283NOYES
CVE-2021-37344CRITICAL
Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection)
Aug 13, 20219.881NONO
CVE-2018-8735HIGH
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command in
Apr 18, 20188.880NOYES
View all 301 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products301 CVEs
50%
34%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local28 (9.3%)
Network242 (80.4%)
Unknown28 (9.3%)
Physical0 (0.0%)
Adjacent Network3 (1.0%)
Attack Complexity
Low269 (89.4%)
High4 (1.3%)
Unknown28 (9.3%)
User Interaction
None162 (53.8%)
Unknown28 (9.3%)
Required111 (36.9%)
Privileges Required
Low144 (47.8%)
High35 (11.6%)
None94 (31.2%)
Unknown28 (9.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (301 CVEs).

CISA KEV
4 CVEs
1.3% of CVEs· 99th percentile
Metasploit
17 CVEs
5.6% of CVEs· 98th percentile
Nuclei
12 CVEs
4.0% of CVEs· 95th percentile
ExploitDB
26 CVEs
8.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nagios.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nagios — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nagios's Products

View all 8 CNAs →

Top CWEs