Adiscon develops a focused set of Windows-based logging, monitoring, and credential-management products including LogAnalyzer, WinSyslog, and Password Manager for IIS that occupy a specialized but strategically important niche in enterprise visibility and access-control infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, driven by the recurrence of application-layer input-handling flaws such as cross-site scripting, SQL injection, and buffer-boundary violations across products that often sit on internally trusted networks but face exposure through web interfaces and administrative roles. Defenders should treat Adiscon product updates with priority and inventory instances that expose logging or credential-management functionality; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adiscon over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19877MEDIUM login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field. | Dec 5, 2018 | 6.1 | 49 | NO | YES |
CVE-2023-34600CRITICAL Adiscon LogAnalyzer v4.1.13 and before is vulnerable to SQL Injection. | Jun 20, 2023 | 9.8 | 42 | NO | NO |
CVE-2023-36306MEDIUM A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, in | Aug 8, 2023 | 6.1 | 36 | NO | YES |
CVE-2022-36664MEDIUM Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter. | Dec 26, 2022 | 6.1 | 32 | NO | YES |
CVE-2003-1518HIGH Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog message. | Dec 31, 2003 | 7.8 | 32 | NO | YES |
CVE-2014-6070MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index. | Sep 11, 2014 | 4.3 | 28 | NO | YES |
CVE-2021-31738MEDIUM Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. | Jun 8, 2021 | 6.1 | 19 | NO | NO |
CVE-2012-3790MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Adiscon LogAnalyzer before 3.4.4 and 3.5.x before 3.5.5 allows remote attackers to inject arbitrary web script or HTML via | Jun 20, 2012 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adiscon.
Media articles that mention a CVE ID that affects a product developed by Adiscon — matched by CVE ID, not by vendor name.