Nagios Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Nagios products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

5

In CISA KEV

4

Beyond CISA KEV

1

Sensor Observed

0

Virtual Patch Available

0

Nagios KEVs Added by Year

Loading...

5 Nagios KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2018-10737

A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter.

High Not in CISA 25 Apr 2025
CVE-2019-15949

Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the...

Confirmed In CISA 03 Nov 2021
CVE-2021-25298

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...

Confirmed In CISA 18 Jan 2022
CVE-2021-25297

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...

Confirmed In CISA 18 Jan 2022
CVE-2021-25296

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file...

Confirmed In CISA 18 Jan 2022

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology