Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
312021.3%HIGH

Related CVEs

12
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-66361An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.MEDIUM6.916.1%Nov 28, 2025
CVE-2025-66360An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. This can lead to privilege escalation.MEDIUM6.917.1%Nov 28, 2025
CVE-2025-66359An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerability.MEDIUM6.15.6%Nov 28, 2025
CVE-2024-56087An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.MEDIUM5.920.0%Dec 16, 2024
CVE-2024-56086An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.HIGH7.131.8%Dec 16, 2024
CVE-2024-56085An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.MEDIUM5.920.0%Dec 16, 2024
CVE-2024-56084An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.HIGH7.123.4%Dec 16, 2024
CVE-2024-48954An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.MEDIUM6.433.5%Nov 7, 2024
CVE-2024-48953An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.HIGH7.523.4%Nov 7, 2024
CVE-2024-48952An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.MEDIUM6.418.6%Nov 7, 2024
CVE-2024-48951An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.HIGH7.522.9%Nov 7, 2024
CVE-2024-48950An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and authentication.HIGH7.523.8%Nov 7, 2024