JPCERT/CC is a Japanese security coordination center that operates LogonTracer and other specialized cybersecurity and network-analysis tools with a narrowly scoped but security-critical focus. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes center on injection flaws—OS command injection, code injection, and cross-site scripting—along with improper input handling in query logic, reflecting the attack surface of analysis and forensic utilities that process untrusted data. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by JPCERT/CC over time
Of all the CVEs published by JPCERT/CC as a CNA, 0.3% affect products that JPCERT/CC develops as a vendor.
Of all the CVEs published that affect products developed by JPCERT/CC, 100.0% are self-published by JPCERT/CC as a CNA.
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16167CRITICAL LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | Jan 9, 2019 | 9.8 | 85 | NO | YES |
CVE-2026-33277HIGH An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. | Apr 27, 2026 | 8.8 | 37 | NO | NO |
CVE-2018-16168CRITICAL LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors. | Jan 9, 2019 | 9.8 | 29 | NO | NO |
CVE-2026-28704HIGH Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with the privilege of the user inv | Apr 10, 2026 | 7.8 | 28 | NO | NO |
CVE-2018-16166HIGH LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | Jan 9, 2019 | 8.8 | 26 | NO | NO |
CVE-2026-33566MEDIUM There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered. | Apr 27, 2026 | 4.3 | 21 | NO | NO |
CVE-2018-16165MEDIUM Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jan 9, 2019 | 6.1 | 20 | NO | NO |
CVE-2023-38752MEDIUM Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute inform | Aug 9, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-38751MEDIUM Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization inf | Aug 9, 2023 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by JPCERT/CC.
Media articles that mention a CVE ID that affects a product developed by JPCERT/CC — matched by CVE ID, not by vendor name.