Nagios maintains a suite of monitoring and infrastructure-management products—including Nagios XI, the core Nagios engine, Log Server, Fusion, and Network Analyzer—that sit centrally in observability and control layers across enterprise environments, and its vulnerability footprint is correspondingly large and prominent in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a consistent tendency toward public exploit availability, reflecting the appeal of web-facing monitoring platforms and their command-execution capabilities as high-value targets. The exposure recurs across the product line through web-tier and system-integration weakness classes including cross-site scripting, OS command injection, SQL injection, and improper privilege management, which are endemic to monitoring dashboards and their backend integration with monitored infrastructure. Defenders should treat Nagios advisories as high-priority, particularly for internet-exposed instances, and maintain strict access controls around monitoring platforms; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nagios over time
Signals from CVEs in this vendor scope (301 CVEs).
301 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25298HIGH Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due t | Feb 15, 2021 | 8.8 | 97 | YES | YES |
CVE-2019-15949HIGH Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The | Sep 5, 2019 | 8.8 | 97 | YES | YES |
CVE-2021-25296HIGH Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php d | Feb 15, 2021 | 8.8 | 96 | YES | YES |
CVE-2021-25297HIGH Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to im | Feb 15, 2021 | 8.8 | 95 | YES | YES |
CVE-2018-15708CRITICAL Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request. | Nov 14, 2018 | 9.8 | 90 | NO | YES |
CVE-2009-2288HIGH statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters. | Jul 1, 2009 | 7.5 | 84 | NO | YES |
CVE-2021-25299MEDIUM Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization o | Feb 15, 2021 | 6.1 | 83 | NO | YES |
CVE-2020-35578HIGH An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticat | Jan 13, 2021 | 7.2 | 83 | NO | YES |
CVE-2021-37344CRITICAL Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of special elements used in an OS Command (OS Command injection) | Aug 13, 2021 | 9.8 | 81 | NO | NO |
CVE-2018-8735HIGH Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execute arbitrary commands on the target system, aka OS command in | Apr 18, 2018 | 8.8 | 80 | NO | YES |
Signals from CVEs in this vendor scope (301 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nagios.
Media articles that mention a CVE ID that affects a product developed by Nagios — matched by CVE ID, not by vendor name.