Skip to content
Noroxi

Graylog records

22 published records for vendor graylog.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
59.1%
Median publish → KEV
No record has entered KEV

All records

22 records
  • graylog2-server vulnerable to instantiation of arbitrary classes triggered by API request

    HighCVSS 8.8Proof of conceptEPSS 35%

    graylog · graylogFeb 7, 2024

  • A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked s

    CriticalCVSS 9.8No exploitEPSS 1%

    graylog · graylogJul 31, 2021

  • A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sessio

    CriticalCVSS 9.8No exploitEPSS 1%

    graylog · graylogJul 31, 2021

  • CVE-2026-1435
    37Monitor

    Incorrect management of session invalidation vulnerability in Graylog Web Interface

    CriticalCVSS 9.3No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • Graylog vulnerable to privilege escalation through API tokens

    HighCVSS 8.8No exploitEPSS 1%

    graylog · graylogJul 2, 2025

  • Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.

    HighCVSS 8.1No exploitEPSS 1%

    graylog · graylogJul 17, 2020

  • Graylog can leak other users' reports via concurrent PDF report rendering

    HighCVSS 7.1No exploitEPSS 1%

    graylog · graylogNov 18, 2024

  • CVE-2026-1436
    28Monitor

    Improper Access Control (IDOR) vulnerability in Graylog Web Interface

    HighCVSS 7.1No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/Que

    MediumCVSS 6.1No exploitEPSS 1%

    graylog · graylogJul 18, 2018

  • Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

    MediumCVSS 6.1No exploitEPSS 1%

    graylog · graylogJun 1, 2018

  • Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, compo

    MediumCVSS 6.1No exploitEPSS 1%

    graylog · graylogJun 1, 2018

  • Insecure source port usage for DNS queries in Graylog

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogAug 31, 2023

  • Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogApr 7, 2025

  • Graylog Allows Session Takeover via Insufficient HTML Sanitization

    MediumCVSS 5.4No exploitEPSS 0%

    graylog · graylogMay 7, 2025

  • CVE-2026-1437
    21Monitor

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • CVE-2026-1441
    21Monitor

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • CVE-2026-1440
    21Monitor

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • CVE-2026-1438
    21Monitor

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • CVE-2026-1439
    21Monitor

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    MediumCVSS 5.3No exploitEPSS 0%

    graylog · graylogFeb 18, 2026

  • graylog2-server Session Fixation vulnerability through cookie injection

    MediumCVSS 4.4No exploitEPSS 0%

    graylog · graylogFeb 7, 2024

  • Partial path traversal vulnerability in Support Bundle feature of Graylog

    LowCVSS 3.8Proof of conceptEPSS 1%

    graylog · graylogAug 31, 2023

  • User session is still usable after logout in graylog2-server

    LowCVSS 3.1No exploitEPSS 0%

    graylog · graylogAug 30, 2023