Logpoint / Siem
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-66361 | An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load. | MEDIUM | 6.9 | Nov 27, 2025 |
| CVE-2025-66360 | An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) informatio… | MEDIUM | 6.9 | Nov 27, 2025 |
| CVE-2025-66359 | An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scri… | HIGH | 8.5 | Nov 27, 2025 |
| CVE-2024-56087 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading… | MEDIUM | 5.9 | Dec 16, 2024 |
| CVE-2024-56086 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is in… | HIGH | 7.1 | Dec 16, 2024 |
| CVE-2024-56085 | An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading… | MEDIUM | 5.9 | Dec 16, 2024 |
| CVE-2024-48954 | An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution. | MEDIUM | 6.4 | Nov 7, 2024 |
| CVE-2024-48953 | An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization c… | HIGH | 7.5 | Nov 7, 2024 |
| CVE-2024-48951 | An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication… | HIGH | 7.5 | Nov 7, 2024 |
| CVE-2024-48950 | An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF… | HIGH | 7.5 | Nov 7, 2024 |
| CVE-2024-33860 | An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an arbitrary File Path is used within the File System Collector. Th… | MEDIUM | 6.5 | May 7, 2024 |
| CVE-2024-33859 | An issue was discovered in Logpoint before 7.4.0. HTML code sent through logs wasn't being escaped in the "Interesting Field" Web UI, leading to XSS. | MEDIUM | 6.1 | May 7, 2024 |
| CVE-2024-33858 | An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could… | MEDIUM | 5.3 | May 7, 2024 |
| CVE-2024-33857 | An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the sy… | CRITICAL | 9.6 | May 7, 2024 |
| CVE-2024-33856 | An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot Password end… | MEDIUM | 5.3 | May 7, 2024 |
| CVE-2024-30176 | In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets. | MEDIUM | 5.3 | May 1, 2024 |
| CVE-2022-48685 | An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leadi… | HIGH | 7.7 | Apr 27, 2024 |
| CVE-2022-48684 | An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating… | HIGH | 8.8 | Apr 27, 2024 |
| CVE-2024-29865 | Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. | MEDIUM | 5.4 | Mar 22, 2024 |
| CVE-2023-49950 | The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template i… | MEDIUM | 5.4 | Feb 3, 2024 |
Showing 1 to 20 of 20 CVEs