Nagios Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Nagios products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
5
In CISA KEV
4
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Nagios KEVs Added by Year
5 Nagios KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2018-10737
A SQL injection issue was discovered in Nagios XI before 5.4.13 via the admin/logbook.php txtSearch parameter. |
XI | High | Not in CISA | 25 Apr 2025 |
|
CVE-2019-15949
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the... |
XI | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-25298
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file... |
Nagios XI | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2021-25297
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file... |
Nagios XI | Confirmed | In CISA | 18 Jan 2022 |
|
CVE-2021-25296
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file... |
Nagios XI | Confirmed | In CISA | 18 Jan 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 3
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology