Перейти к содержимому
Noroxi

Записи Graylog

22 опубликованных записей вендора graylog.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
59,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

22 записей
  • CVE-2024-24824
    45В плане

    graylog2-server vulnerable to instantiation of arbitrary classes triggered by API request

    ВысокаяCVSS 8,8Proof of conceptEPSS 35 %

    graylog · graylog7 февр. 2024 г.

  • CVE-2021-37759
    39Наблюдать

    A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked s

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    graylog · graylog31 июл. 2021 г.

  • CVE-2021-37760
    39Наблюдать

    A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sessio

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    graylog · graylog31 июл. 2021 г.

  • CVE-2026-1435
    37Наблюдать

    Incorrect management of session invalidation vulnerability in Graylog Web Interface

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2025-53106
    35Наблюдать

    Graylog vulnerable to privilege escalation through API tokens

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    graylog · graylog2 июл. 2025 г.

  • CVE-2020-15813
    32Наблюдать

    Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    graylog · graylog17 июл. 2020 г.

  • CVE-2024-52506
    28Наблюдать

    Graylog can leak other users' reports via concurrent PDF report rendering

    ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %

    graylog · graylog18 нояб. 2024 г.

  • CVE-2026-1436
    28Наблюдать

    Improper Access Control (IDOR) vulnerability in Graylog Web Interface

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2018-14380
    24Наблюдать

    In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/Que

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    graylog · graylog18 июл. 2018 г.

  • CVE-2018-11650
    24Наблюдать

    Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    graylog · graylog1 июн. 2018 г.

  • CVE-2018-11651
    24Наблюдать

    Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, compo

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    graylog · graylog1 июн. 2018 г.

  • CVE-2023-41045
    21Наблюдать

    Insecure source port usage for DNS queries in Graylog

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog31 авг. 2023 г.

  • CVE-2025-30373
    21Наблюдать

    Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog7 апр. 2025 г.

  • CVE-2025-46827
    21Наблюдать

    Graylog Allows Session Takeover via Insufficient HTML Sanitization

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    graylog · graylog7 мая 2025 г.

  • CVE-2026-1437
    21Наблюдать

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2026-1441
    21Наблюдать

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2026-1440
    21Наблюдать

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2026-1438
    21Наблюдать

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2026-1439
    21Наблюдать

    Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    graylog · graylog18 февр. 2026 г.

  • CVE-2024-24823
    17Наблюдать

    graylog2-server Session Fixation vulnerability through cookie injection

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    graylog · graylog7 февр. 2024 г.

  • CVE-2023-41044
    15Наблюдать

    Partial path traversal vulnerability in Support Bundle feature of Graylog

    НизкаяCVSS 3,8Proof of conceptEPSS 1 %

    graylog · graylog31 авг. 2023 г.

  • CVE-2023-41041
    12Наблюдать

    User session is still usable after logout in graylog2-server

    НизкаяCVSS 3,1Эксплойта нетEPSS 0 %

    graylog · graylog30 авг. 2023 г.