Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-66360 An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) … Siem 7.7.0+ Fix from $1,9502025-11-28 MEDIUM 6.5 CVE-2025-66361 An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load. Siem 7.7.0+ Fix from $1,6002025-11-28 MEDIUM 6.1 CVE-2025-66359 An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross… Siem 7.7.0+ Fix from $1,6002025-11-28 HIGH 7.1 CVE-2024-56084 An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. Th… Universal Normalizer 5.7.0+ Fix from $1,9502024-12-16 HIGH 7.1 CVE-2024-56086 An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup pro… Siem 7.5.0+ Fix from $1,9502024-12-16 MEDIUM 5.9 CVE-2024-56085 An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are execute… Siem 7.5.0+ Fix from $1,6002024-12-16 MEDIUM 5.9 CVE-2024-56087 An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are execute… Siem 7.5.0+ Fix from $1,6002024-12-16 HIGH 7.5 CVE-2024-48950 An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to b… Siem 7.5.0+ Fix from $1,9502024-11-07 HIGH 7.5 CVE-2024-48951 An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to auth… Siem 7.5.0+ Fix from $1,9502024-11-07 HIGH 7.5 CVE-2024-48953 An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper autho… Siem 7.5.0+ Fix from $1,9502024-11-07 MEDIUM 6.4 CVE-2024-48952 An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints withou… Soar 7.5.0+ Fix from $1,6002024-11-07 MEDIUM 6.4 CVE-2024-48954 An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code… Siem 7.5.0+ Fix from $1,6002024-11-07 MEDIUM 5.3 CVE-2024-36383 An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL r… Saml Authentication 6.0.3+ Fix from $1,6002024-05-27 MEDIUM 6.5 CVE-2024-33860 An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Col… Siem 7.4.0+ Fix from $1,6002024-05-07 MEDIUM 6.1 CVE-2024-33859 An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS. Siem 7.4.0+ Fix from $1,6002024-05-07 CRITICAL 9.6 CVE-2024-33857 An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access… Siem 7.4.0+ Fix from $2,3002024-05-07 MEDIUM 5.3 CVE-2024-33856 An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Pa… Siem 7.4.0+ Fix from $1,6002024-05-07 MEDIUM 5.3 CVE-2024-33858 An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parame… Siem 7.4.0+ Fix from $1,6002024-05-07 MEDIUM 5.3 CVE-2024-30176 In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets. Siem 7.4.0+ Fix from $1,6002024-05-01 HIGH 8.8 CVE-2022-48684 An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for g… Siem 7.1.1+ Fix from $1,9502024-04-27 MEDIUM 6.7 CVE-2022-48685 An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as r… Siem 7.1.2+ Fix from $1,6002024-04-27 MEDIUM 5.4 CVE-2024-29865 Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. Siem 7.1.0+ Fix from $1,6002024-03-22 MEDIUM 5.4 CVE-2023-49950 The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja … Siem 7.3.0+ Fix from $1,6002024-02-03