Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-1438 Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e… Graylog Mitigation only Fix from $1,6002026-02-18 MEDIUM 6.1 CVE-2026-1439 Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e… Graylog Mitigation only Fix from $1,6002026-02-18 MEDIUM 6.1 CVE-2026-1440 Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e… Graylog Mitigation only Fix from $1,6002026-02-18 MEDIUM 6.1 CVE-2026-1441 Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e… Graylog Mitigation only Fix from $1,6002026-02-18 CRITICAL 9.8 CVE-2026-1435 Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new… Graylog Mitigation only Fix from $2,3002026-02-18 MEDIUM 6.5 CVE-2026-1436 Improper Access Control (IDOR) in the Graylog API, version 2.2.3, which occurs when modifying the user ID in the URL. An authenticated user can acces… Graylog Mitigation only Fix from $1,6002026-02-18 MEDIUM 6.1 CVE-2026-1437 Reflected Cross-Site Scripting (XSS) vulnerability in the Graylog Web Interface console, version 2.2.3, caused by a lack of proper sanitization and e… Graylog Mitigation only Fix from $1,6002026-02-18 HIGH 8.8 CVE-2025-53106 Graylog is a free and open log management platform. In versions 6.2.0 to before 6.2.4 and 6.3.0-alpha.1 to before 6.3.0-rc.2, Graylog users can gain … Graylog 6.2.4+ Fix from $1,9502025-07-02 MEDIUM 5.4 CVE-2025-46827 Graylog is a free and open log management platform. Prior to versions 6.0.14, 6.1.10, and 6.2.0, it is possible to obtain user session cookies by sub… Graylog 6.0.14 / 6.1.10+ Fix from $1,6002025-05-07 MEDIUM 5.3 CVE-2025-30373 Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and ha… Graylog 6.1.9+ Fix from $1,6002025-04-07 MEDIUM 6.5 CVE-2024-52506 Graylog is a free and open log management platform. The reporting functionality in Graylog allows the creation and scheduling of reports which contai… Graylog 6.1.2+ Fix from $1,6002024-11-18 HIGH 8.8 CVE-2024-24824EPSS 34% Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded… Graylog 5.1.11 / 5.2.4+ Fix from $1,9502024-02-07 MEDIUM 5.3 CVE-2023-41045 Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket f… Graylog 5.0.9 / 5.1.3+ Fix from $1,6002023-08-31 CRITICAL 9.8 CVE-2021-37759 A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID… Graylog 4.1.2+ Fix from $2,3002021-07-31 CRITICAL 9.8 CVE-2021-37760 A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). Graylog 4.1.2+ Fix from $2,3002021-07-31 HIGH 8.1 CVE-2020-15813 Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers. It allows use of an external user/group database stored in LDAP. The connecti… Graylog 3.3.3+ Fix from $1,9502020-07-17 MEDIUM 6.1 CVE-2018-14380 In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.t… Graylog 2.4.6+ Fix from $1,6002018-07-18 MEDIUM 6.1 CVE-2018-11650 Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js. Graylog 2.4.4+ Fix from $1,6002018-06-01 MEDIUM 6.1 CVE-2018-11651 Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/das… Graylog 2.4.4+ Fix from $1,6002018-06-01