In Nagios XI versions prior to 2026R1 a high severity vulnerability CVE-2025-34227 was detected. This authenticated command injection issue affects the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query configuration wizards. By injecting shell characters into service arguments, an attacker could execute arbitrary system commands on the underlying host as the nagios user. To address this issue, users should upgrade to Nagios XI 2026R1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-34227.
Read more MonitoringIn Zabbix Server versions 6.0.0 through 6.0.33, 6.4.0 through 6.4.18, and 7.0.0 through 7.0.3 a medium severity vulnerability CVE-2025-27240 was detected. This vulnerability allows a Zabbix administrator to inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the ‘Visible name’ field. To address this issue, users should upgrade Zabbix to versions 6.0.34, 6.4.19, 7.0.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27240.
Read more MonitoringIn Zabbix version 5.0 a medium severity vulnerability CVE-2025-27234 was detected. This vulnerability allows attackers to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this can result in remote code execution. To address this issue, users should upgrade Zabbix to version 5.0.47 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27234.
Read more MonitoringIn Zabbix versions 6.0.0 through 6.0.39, 7.0.0 through 7.0.10, and 7.2.0 through 7.2.4 a medium severity vulnerability CVE-2025-27233 was detected. This vulnerability allows attackers to inject unexpected arguments into the smartctl command via the smart.disk.get parameters, which can be exploited to leak the NTLMv2 hash from a Windows system. To address this issue, users should upgrade Zabbix Agent 2 to versions 6.0.40, 7.0.11, 7.2.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27233.
Read more MonitoringIn Zabbix versions 7.0.0 through 7.0.13 and 7.2.0 through 7.2.7 a medium severity vulnerability CVE-2025-27238 was detected. This vulnerability allows users without any assigned user groups to retrieve information on all host prototypes via the hostprototype.get API method. To address this issue, users should upgrade Zabbix to versions 7.0.14 or 7.2.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27238.
Read more MonitoringIn Nagios XI versions prior to 2024R1.3.2 a high severity vulnerability CVE-2024-13986 was detected. This vulnerability allows an authenticated attacker to achieve remote code execution by chaining an arbitrary file upload with a path traversal in the Core Config Snapshots interface. To address this issue, users should upgrade Nagios XI to versions 2024R1.3.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13986.
Read more MonitoringIn LibreNMS versions 25.6.0 and prior a medium severity vulnerability CVE-2025-55296 was detected. This vulnerability allows attackers to inject malicious JavaScript into the Alert Template name field, which can then be executed when the template is viewed by other administrators. To address this issue, users should upgrade LibreNMS to versions 25.8.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-55296.
Read more MonitoringIn Sentry versions prior to 25.5.0 a high severity vulnerability CVE-2025-53099 was detected. This vulnerability allows attackers with a malicious OAuth application to exploit a race condition and improper authorization code handling during the OAuth exchange process, enabling them to maintain persistent access to a user’s account even after the application is de-authorized. To address this issue users must upgrade to version 25.5.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53099.
Read more MonitoringIn Sentry versions 25.1.0 through 25.5.1 a medium severity vulnerability CVE-2025-53073 was detected. This vulnerability allows authenticated attackers to perform unauthorized actions, such as adding comments, on a project’s issue endpoint without being a member of the project’s team. Currently there is no fix for this vulnerability. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53073.
Read more Monitoring