Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has write access to '/usr/local/nagioslogserver/scripts', while several scripts in this directory are owned by root and may be executed via sudo without a password. A local attacker running as 'www-data' can move one of these root-owned scripts to a backup name and create a replacement script with attacker-controlled content at the original path, then invoke it with sudo. This allows arbitrary commands to be executed with root privileges, providing full compromise of the underlying operating system. Join the discussion | CVE Database V5 | 11/17/2025, 17:48:28 UTC Added: 11/17/2025, 18:04:14 UTC |
CVE-2023-7321 is a medium-severity cross-site scripting (XSS) vulnerability affecting Nagios Log Server versions prior to 2.1.14. The issue arises from improper encoding of untrusted log content on the Snapshots Page, allowing attacker-supplied data in logs to execute scripts in users' browsers within the application origin. Exploitation requires no authentication but does require user interaction, such as viewing a maliciously crafted snapshot. While no known exploits are currently in the wild, the vulnerability could enable attackers to perform actions like session hijacking or delivering malicious payloads to users. European organizations using Nagios Log Server should prioritize patching to mitigate risks. Countries with significant Nagios usage and critical infrastructure monitoring are at higher risk. Mitigation includes upgrading to version 2.1. Join the discussion | CVE Database V5 | 10/30/2025, 21:27:23 UTC Added: 10/30/2025, 21:40:50 UTC |
CVE-2023-7323 is a medium-severity cross-site scripting (XSS) vulnerability affecting Nagios Log Server versions prior to 2024R1. The flaw exists in the Create User function due to improper neutralization of user input, allowing attackers to inject malicious scripts that execute in the victim's browser context. Exploitation requires low privileges and user interaction but no authentication. While no known exploits are currently reported in the wild, successful attacks could lead to session hijacking, credential theft, or unauthorized actions within the affected web application. European organizations using vulnerable Nagios Log Server versions are at risk, especially those in critical infrastructure and IT monitoring roles. Mitigation involves upgrading to version 2024R1 or later and implementing strict input validation and output encoding on user-supplied data. Countries with significant Nagios deployments and critical infrastructure monitoring, such as Germany, France, and the UK, are most likely to be affected. Due to the medium CVSS score and the nature of the vulnerability, organizations should prioritize patching to prevent potential exploitation. Join the discussion | CVE Database V5 | 10/30/2025, 21:27:03 UTC Added: 10/30/2025, 21:40:50 UTC |
Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls. Join the discussion | CVE Database V5 | 10/30/2025, 21:25:52 UTC Added: 10/30/2025, 21:40:52 UTC |
0 CVE-2025-34277 is a critical code injection vulnerability in Nagios Log Server versions prior to 2024R1.3.1. It arises from improper validation of dashboard ID inputs, allowing attackers to inject and execute arbitrary code within the Log Server process. The vulnerability requires no user interaction but does require low-level privileges, making exploitation feasible in environments where an attacker has limited access. Successful exploitation can lead to full compromise of the affected system, impacting confidentiality, integrity, and availability. No public exploits are known yet, but the high CVSS score (9.4) indicates severe risk. European organizations using Nagios Log Server should prioritize patching and implement strict input validation and monitoring controls. Countries with significant Nagios deployments and critical infrastructure reliance on this product are at higher risk. Join the discussion | CVE Database V5 | 10/30/2025, 21:25:32 UTC Added: 10/30/2025, 21:40:52 UTC |
0 CVE-2025-34272 is a medium-severity vulnerability in Nagios Log Server versions prior to 2024R2.0.3. When a user's configured default dashboard is deleted, the application may incorrectly display another user's dashboard as the default, potentially exposing sensitive information or privileges. This occurs due to improper fallback handling in the dashboard selection logic. The vulnerability does not require user interaction or authentication beyond low privileges, and it can be exploited remotely over the network. Although no known exploits are currently in the wild, affected organizations should prioritize patching to prevent unauthorized data exposure. European organizations using Nagios Log Server for log management and monitoring are at risk, especially those with complex dashboard sharing policies. Countries with high adoption of Nagios products and critical infrastructure monitoring are more likely to be targeted. Mitigation involves updating to version 2024R2. Join the discussion | CVE Database V5 | 10/30/2025, 21:25:10 UTC Added: 10/30/2025, 21:40:51 UTC |
CVE-2025-34273 is a high-severity incorrect authorization vulnerability in Nagios Log Server versions prior to 2024R2.0.3. It allows non-administrator users to delete global dashboards due to improper enforcement of authorization checks. This flaw can disrupt monitoring visibility for all users by removing shared dashboards critical to organizational operations. The vulnerability requires only low privileges and no user interaction, making exploitation relatively straightforward. Although no known exploits are reported in the wild, the impact on availability and integrity of monitoring data is significant. European organizations relying on Nagios Log Server for centralized log management and monitoring are at risk, especially those with multi-user environments. Mitigation involves upgrading to version 2024R2.0. Join the discussion | CVE Database V5 | 10/30/2025, 21:24:43 UTC Added: 10/30/2025, 21:40:51 UTC |
CVE-2024-58273 is a high-severity local privilege escalation vulnerability in Nagios Log Server versions prior to 2024R1.0.2. It allows an attacker with the ability to execute commands as the Apache web user or backend shell user to escalate privileges to root on the host system. The vulnerability stems from incorrect privilege assignment (CWE-266), enabling unauthorized elevation of privileges without user interaction. Exploitation requires local access with limited privileges but no authentication bypass or user interaction. No known exploits are currently reported in the wild. This vulnerability poses a significant risk to systems running affected Nagios Log Server versions, especially in environments where the Apache user has command execution capabilities. European organizations using Nagios Log Server should prioritize patching to prevent potential root compromise. The CVSS 4. Join the discussion | CVE Database V5 | 10/30/2025, 21:24:15 UTC Added: 10/30/2025, 21:40:51 UTC |
CVE-2025-34274 is a critical vulnerability in Nagios Log Server versions prior to 2024R2.0.3 where the embedded Logstash process runs with root privileges. An attacker exploiting this flaw via insecure plugins, pipeline configuration injection, or input parsing vulnerabilities could execute arbitrary code with root access, leading to full system compromise. The vulnerability arises from execution with unnecessary privileges (CWE-250). Nagios has mitigated this risk in newer versions by running Logstash under a lower-privileged 'nagios' user. The CVSS 4.0 score is 9.3, reflecting the high impact and ease of exploitation without authentication or user interaction. European organizations using affected Nagios Log Server versions face significant risks, especially critical infrastructure and enterprises relying on this logging solution. Join the discussion | CVE Database V5 | 10/30/2025, 21:23:54 UTC Added: 10/30/2025, 21:40:51 UTC |
CVE-2023-7322 is a high-severity incorrect authorization vulnerability in Nagios Log Server versions prior to 2024R1. Authenticated users with limited privileges can exploit this flaw to access or modify data and perform actions beyond their authorization via the API. The vulnerability arises from improper authorization checks on API endpoints, allowing privilege escalation without requiring user interaction or elevated authentication. Although no known exploits are currently reported in the wild, the vulnerability's CVSS score of 8.7 indicates a significant risk. European organizations using Nagios Log Server for log management and monitoring could face data confidentiality and integrity breaches, as well as potential disruption of monitoring services. Mitigation requires prompt upgrading to version 2024R1 or later, strict API access controls, and monitoring of user activities. Countries with high adoption of Nagios products and critical infrastructure monitoring, such as Germany, France, and the UK, are particularly at risk. Given the ease of exploitation and the broad impact on data and system integrity, this vulnerability demands urgent attention from defenders. Join the discussion | CVE Database V5 | 10/30/2025, 21:23:34 UTC Added: 10/30/2025, 21:40:50 UTC |
Showing 1 to 10 of 12 results