Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Graylog MEDIUM 6.1
CVE-2026-1438

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e…

Mitigation only
Fix from $1,600 2026-02-18
Graylog MEDIUM 6.1
CVE-2026-1439

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e…

Mitigation only
Fix from $1,600 2026-02-18
Graylog MEDIUM 6.1
CVE-2026-1440

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e…

Mitigation only
Fix from $1,600 2026-02-18
Graylog MEDIUM 6.1
CVE-2026-1441

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e…

Mitigation only
Fix from $1,600 2026-02-18
Graylog CRITICAL 9.8
CVE-2026-1435

Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new…

Mitigation only
Fix from $2,300 2026-02-18
Graylog MEDIUM 6.5
CVE-2026-1436

Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can acces…

Mitigation only
Fix from $1,600 2026-02-18
Graylog MEDIUM 6.1
CVE-2026-1437

Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e…

Mitigation only
Fix from $1,600 2026-02-18
Graylog HIGH 8.8
CVE-2025-53106

Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain …

Fix: 6.2.4+
Fix from $1,950 2025-07-02
Graylog MEDIUM 5.4
CVE-2025-46827

Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by sub…

Fix: 6.0.14 / 6.1.10+
Fix from $1,600 2025-05-07
Graylog MEDIUM 5.3
CVE-2025-30373

Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and ha…

Fix: 6.1.9+
Fix from $1,600 2025-04-07
Graylog MEDIUM 6.5
CVE-2024-52506

Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contai…

Fix: 6.1.2+
Fix from $1,600 2024-11-18
Graylog HIGH 8.8
CVE-2024-24824EPSS 34%

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded…

Fix: 5.1.11 / 5.2.4+
Fix from $1,950 2024-02-07
Graylog MEDIUM 5.3
CVE-2023-41045

Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket f…

Fix: 5.0.9 / 5.1.3+
Fix from $1,600 2023-08-31
Graylog CRITICAL 9.8
CVE-2021-37759

A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID…

Fix: 4.1.2+
Fix from $2,300 2021-07-31
Graylog CRITICAL 9.8
CVE-2021-37760

A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

Fix: 4.1.2+
Fix from $2,300 2021-07-31
Graylog HIGH 8.1
CVE-2020-15813

Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connecti…

Fix: 3.3.3+
Fix from $1,950 2020-07-17
Graylog MEDIUM 6.1
CVE-2018-14380

In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.t…

Fix: 2.4.6+
Fix from $1,600 2018-07-18
Graylog MEDIUM 6.1
CVE-2018-11650

Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

Fix: 2.4.4+
Fix from $1,600 2018-06-01
Graylog MEDIUM 6.1
CVE-2018-11651

Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/das…

Fix: 2.4.4+
Fix from $1,600 2018-06-01