📦 Siem

by Logpoint

🔍 What is Siem?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33857

CRITICAL CVSS 9.6 May 7, 2024

A Server-Side Request Forgery (SSRF) vulnerability in Logpoint versions before 7.4.0 allows attackers with low-level access to make unauthorized requests from the server. This occurs due to insufficie...

CVE-2025-66359

HIGH CVSS 8.5 Nov 28, 2025

This cross-site scripting (XSS) vulnerability in Logpoint allows attackers to inject malicious scripts into web pages viewed by other users. It affects all Logpoint deployments running versions before...

CVE-2025-66360

HIGH CVSS 8.8 Nov 28, 2025

Logpoint versions before 7.7.0 have an access control misconfiguration that allows li-admin users to access sensitive Redis service information. This exposure can enable privilege escalation attacks. ...

CVE-2024-56086

HIGH CVSS 7.1 Dec 16, 2024

Authenticated users in Logpoint versions before 7.5.0 can inject malicious payloads into Report Templates. When backups are initiated, these payloads execute, allowing remote code execution on the Log...

CVE-2024-48951

HIGH CVSS 7.5 Nov 7, 2024

A Server-Side Request Forgery (SSRF) vulnerability in Logpoint SOAR allows attackers to make the server send requests to internal systems, potentially leaking the Logpoint API token. This token leak c...

CVE-2024-48953

HIGH CVSS 7.5 Nov 7, 2024

This vulnerability allows unauthenticated attackers to register custom authentication plugins in Logpoint, bypassing normal authentication mechanisms. Any Logpoint deployment before version 7.5.0 is a...

CVE-2022-48684

HIGH CVSS 8.4 Apr 27, 2024

This CVE describes a template injection vulnerability in Logpoint's search template feature that uses Jinja templating. Any authenticated user with search template creation privileges can exploit this...

CVE-2025-66361

MEDIUM CVSS 6.5 Nov 28, 2025

Logpoint versions before 7.7.0 expose sensitive information in system processes during high CPU load conditions. This affects all Logpoint deployments running vulnerable versions, potentially exposing...

CVE-2024-33860

MEDIUM CVSS 6.5 May 7, 2024

This Local File Inclusion vulnerability in Logpoint versions before 7.4.0 allows attackers to read arbitrary files on the system through the File System Collector. Attackers can view sensitive file co...

CVE-2024-33856

MEDIUM CVSS 5.3 May 7, 2024

This vulnerability in Logpoint allows attackers to enumerate valid usernames by timing responses from the Forgot Password endpoint. Attackers can identify which usernames exist in the system, facilita...