CVE Tools

Log Server

24 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Log Server, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Log Server CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Log Server CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-060
2025-070
2025-081
2025-090
2025-1015
2025-112
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical417%
  • High729%
  • Medium1354%

Latest CVEs

The 15 most recently published vulnerabilities affecting Log Server.

  1. CVE-2025-34323Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules7.8
  2. CVE-2025-34322Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries7.2
  3. CVE-2023-7321Nagios Log Server < 2.1.14 XSS via Snapshots Page5.4
  4. CVE-2023-7323Nagios Log Server < 2024R1 XSS via Create User Function5.4
  5. CVE-2020-36858Nagios Log Server < 2.1.6 XSS via Create User, Edit User, & Manage Host Lists Pages5.4
  6. CVE-2025-34298Nagios Log Server < 2024R1.3.2 Set Email Privilege Escalation8.8
  7. CVE-2025-34277Nagios Log Server < 2024R1.3.1 RCE via Malformed Dashboard ID9.8
  8. CVE-2025-34272Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback6.5
  9. CVE-2025-34273Nagios Log Server < 2024R2.0.3 Non-Admin Dashboard Deletion6.5
  10. CVE-2024-58273Nagios Log Server < 2024R1.0.2 LPE from Apache/Backend Shell User to Root7.8
  11. CVE-2025-34274Nagios Log Server < 2024R2.0.3 Logstash Process Root Privileges9.8
  12. CVE-2023-7322Nagios Log Server < 2024R1 Incorrect Authorization Granting Full API Access8.1
  13. CVE-2016-15049Nagios Log Server < 1.4.2 Dashboards Logs Table XSS5.4
  14. CVE-2025-34271Nagios Log Server < 2024R2.0.2 Cluster Manager Credential Requests Sent Over Plaintext9.8
  15. CVE-2025-34270Nagios Log Server < 2024R2.0.2 AD/LDAP Import Password Not Obfuscated4.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store