KoreLogic Security
First CVE: Aug 7, 2024Active for: 2 years
19
CVEs Published
More CVEs Published than 38% of tracked CNAs
6.3
Avg CVEs / Year
More Avg CVEs / Year than 39% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 70% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by KoreLogic Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2024
23 months ago
Most Recent CVE
Jan 8, 2026
197 days ago
Top CVEs
All CVEs published by KoreLogic Security as a CNA, regardless of affected vendor or product.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8503CRITICAL An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials withi | Sep 10, 2024 | 9.8 | 87 | NO | YES |
CVE-2024-8504HIGH An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute ar | Sep 10, 2024 | 8.8 | 79 | NO | YES |
CVE-2024-6893HIGH The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform | Aug 8, 2024 | 7.5 | 50 | NO | YES |
CVE-2025-54769HIGH An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrit | Jul 29, 2025 | 8.8 | 41 | NO | YES |
CVE-2024-6892MEDIUM Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application. | Aug 8, 2024 | 6.1 | 27 | NO | YES |
CVE-2025-5099CRITICAL An Out of Bounds Write occurs when the native library attempts PDF rendering, which can be exploited to achieve memory corruption and potentially arbitrary code execution. | May 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-15464HIGH Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, bypassing security controls. | Jan 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2024-6891HIGH Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow. | Aug 8, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-6707HIGH Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability. | Aug 7, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-5098CRITICAL PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization. | May 23, 2025 | 9.1 | 24 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA19 CVEs
37%
47%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.3%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (84.2%)
Unknown0 (0.0%)
Required3 (15.8%)
Privileges Required
Low7 (36.8%)
High1 (5.3%)
None11 (57.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
10.5% of CVEs· 98th percentile
Nuclei
3 CVEs
15.8% of CVEs· 99th percentile
ExploitDB
1 CVE
5.3% of CVEs· 95th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by KoreLogic Security as a CNA.
Media Mentions
Media articles that mention a CVE ID published by KoreLogic Security as a CNA — matched by CVE ID, not by organization name.