Записи Graylog
22 опубликованных записей вендора graylog.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 59,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-532 Insertion of Sensitive Information into Log File2
- CWE-613 Insufficient Session Expiration2
- CWE-285 Improper Authorization2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-384 Session Fixation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
22 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2024-24824Proof of concept | graylog2-server vulnerable to instantiation of arbitrary classes triggered by API requestgraylog · graylog · CWE-284 | Высокая8,8 | — | 34,7 % | 7 февр. 2024 г. |
39Наблюдать | CVE-2021-37759Эксплойта нет | A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sgraylog · graylog · CWE-532 | Критическая9,8 | — | 1,3 % | 31 июл. 2021 г. |
39Наблюдать | CVE-2021-37760Эксплойта нет | A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sessiograylog · graylog · CWE-532 | Критическая9,8 | — | 1,3 % | 31 июл. 2021 г. |
37Наблюдать | CVE-2026-1435Эксплойта нет | Incorrect management of session invalidation vulnerability in Graylog Web Interfacegraylog · graylog · CWE-613 | Критическая9,3 | — | 0,4 % | 18 февр. 2026 г. |
35Наблюдать | CVE-2025-53106Эксплойта нет | Graylog vulnerable to privilege escalation through API tokensgraylog · graylog · CWE-285 | Высокая8,8 | — | 0,6 % | 2 июл. 2025 г. |
32Наблюдать | CVE-2020-15813Эксплойта нет | Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.graylog · graylog · CWE-295 | Высокая8,1 | — | 0,8 % | 17 июл. 2020 г. |
28Наблюдать | CVE-2024-52506Эксплойта нет | Graylog can leak other users' reports via concurrent PDF report renderinggraylog · graylog · CWE-200 | Высокая7,1 | — | 0,6 % | 18 нояб. 2024 г. |
28Наблюдать | CVE-2026-1436Эксплойта нет | Improper Access Control (IDOR) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-639 | Высокая7,1 | — | 0,2 % | 18 февр. 2026 г. |
24Наблюдать | CVE-2018-14380Эксплойта нет | In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/Quegraylog · graylog · CWE-79 | Средняя6,1 | — | 1,0 % | 18 июл. 2018 г. |
24Наблюдать | CVE-2018-11650Эксплойта нет | Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.graylog · graylog · CWE-79 | Средняя6,1 | — | 0,8 % | 1 июн. 2018 г. |
24Наблюдать | CVE-2018-11651Эксплойта нет | Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, compograylog · graylog · CWE-79 | Средняя6,1 | — | 0,8 % | 1 июн. 2018 г. |
21Наблюдать | CVE-2023-41045Эксплойта нет | Insecure source port usage for DNS queries in Grayloggraylog · graylog · CWE-345 | Средняя5,3 | — | 0,4 % | 31 авг. 2023 г. |
21Наблюдать | CVE-2025-30373Эксплойта нет | Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong valuegraylog · graylog · CWE-285 | Средняя5,3 | — | 0,3 % | 7 апр. 2025 г. |
21Наблюдать | CVE-2025-46827Эксплойта нет | Graylog Allows Session Takeover via Insufficient HTML Sanitizationgraylog · graylog · CWE-79 | Средняя5,4 | — | 0,3 % | 7 мая 2025 г. |
21Наблюдать | CVE-2026-1437Эксплойта нет | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Средняя5,3 | — | 0,2 % | 18 февр. 2026 г. |
21Наблюдать | CVE-2026-1441Эксплойта нет | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Средняя5,3 | — | 0,2 % | 18 февр. 2026 г. |
21Наблюдать | CVE-2026-1440Эксплойта нет | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Средняя5,3 | — | 0,2 % | 18 февр. 2026 г. |
21Наблюдать | CVE-2026-1438Эксплойта нет | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Средняя5,3 | — | 0,2 % | 18 февр. 2026 г. |
21Наблюдать | CVE-2026-1439Эксплойта нет | Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interfacegraylog · graylog · CWE-79 | Средняя5,3 | — | 0,2 % | 18 февр. 2026 г. |
17Наблюдать | CVE-2024-24823Эксплойта нет | graylog2-server Session Fixation vulnerability through cookie injectiongraylog · graylog · CWE-384 | Средняя4,4 | — | 0,4 % | 7 февр. 2024 г. |
15Наблюдать | CVE-2023-41044Proof of concept | Partial path traversal vulnerability in Support Bundle feature of Grayloggraylog · graylog · CWE-22 | Низкая3,8 | — | 0,7 % | 31 авг. 2023 г. |
12Наблюдать | CVE-2023-41041Эксплойта нет | User session is still usable after logout in graylog2-servergraylog · graylog · CWE-613 | Низкая3,1 | — | 0,5 % | 30 авг. 2023 г. |
- CVE-2024-2482445В плане
graylog2-server vulnerable to instantiation of arbitrary classes triggered by API request
ВысокаяCVSS 8,8Proof of conceptEPSS 35 %graylog · graylog7 февр. 2024 г.
- CVE-2021-3775939Наблюдать
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked s
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %graylog · graylog31 июл. 2021 г.
- CVE-2021-3776039Наблюдать
A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked sessio
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %graylog · graylog31 июл. 2021 г.
- CVE-2026-143537Наблюдать
Incorrect management of session invalidation vulnerability in Graylog Web Interface
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2025-5310635Наблюдать
Graylog vulnerable to privilege escalation through API tokens
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %graylog · graylog2 июл. 2025 г.
- CVE-2020-1581332Наблюдать
Graylog before 3.3.3 lacks SSL Certificate Validation for LDAP servers.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %graylog · graylog17 июл. 2020 г.
- CVE-2024-5250628Наблюдать
Graylog can leak other users' reports via concurrent PDF report rendering
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %graylog · graylog18 нояб. 2024 г.
- CVE-2026-143628Наблюдать
Improper Access Control (IDOR) vulnerability in Graylog Web Interface
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2018-1438024Наблюдать
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/Que
СредняяCVSS 6,1Эксплойта нетEPSS 1 %graylog · graylog18 июл. 2018 г.
- CVE-2018-1165024Наблюдать
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %graylog · graylog1 июн. 2018 г.
- CVE-2018-1165124Наблюдать
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, compo
СредняяCVSS 6,1Эксплойта нетEPSS 1 %graylog · graylog1 июн. 2018 г.
- CVE-2023-4104521Наблюдать
Insecure source port usage for DNS queries in Graylog
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog31 авг. 2023 г.
- CVE-2025-3037321Наблюдать
Graylog Authenticated HTTP inputs do ingest message even if Authorization header is missing or has wrong value
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog7 апр. 2025 г.
- CVE-2025-4682721Наблюдать
Graylog Allows Session Takeover via Insufficient HTML Sanitization
СредняяCVSS 5,4Эксплойта нетEPSS 0 %graylog · graylog7 мая 2025 г.
- CVE-2026-143721Наблюдать
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2026-144121Наблюдать
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2026-144021Наблюдать
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2026-143821Наблюдать
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2026-143921Наблюдать
Reflected Cross-Site Scripting (XSS) vulnerability in Graylog Web Interface
СредняяCVSS 5,3Эксплойта нетEPSS 0 %graylog · graylog18 февр. 2026 г.
- CVE-2024-2482317Наблюдать
graylog2-server Session Fixation vulnerability through cookie injection
СредняяCVSS 4,4Эксплойта нетEPSS 0 %graylog · graylog7 февр. 2024 г.
- CVE-2023-4104415Наблюдать
Partial path traversal vulnerability in Support Bundle feature of Graylog
НизкаяCVSS 3,8Proof of conceptEPSS 1 %graylog · graylog31 авг. 2023 г.
- CVE-2023-4104112Наблюдать
User session is still usable after logout in graylog2-server
НизкаяCVSS 3,1Эксплойта нетEPSS 0 %graylog · graylog30 авг. 2023 г.