Nagvis before 1.9.34 was discovered to contain an arbitrary file read vulnerability via the component /core/classes/NagVisHoverUrl.php.
https://www.sonarsource.com/blog/checkmk-rce-chain-3/
https://github.com/NagVis/nagvis/compare/nagvis-1.9.33...nagvis-1.9.34
https://github.com/NagVis/nagvis/commit/71aba7f46f79d846e1df037f165d206a2cd1d22a