Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

JPCERT/CC

First CVE: Jan 9, 2019Active for: 8 yearsTotal CVEs: 9

JPCERT/CC is a Japanese security coordination center that operates LogonTracer and other specialized cybersecurity and network-analysis tools with a narrowly scoped but security-critical focus. Vulnerabilities affecting this vendor skew toward serious outcomes and frequently acquire public exploit code; the recurring weakness classes center on injection flaws—OS command injection, code injection, and cross-site scripting—along with improper input handling in query logic, reflecting the attack surface of analysis and forensic utilities that process untrusted data. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by JPCERT/CC over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 9, 2019
7 years ago
Most Recent CVE
Apr 27, 2026
88 days ago

Self-Reporting Analysis

Of all the CVEs published by JPCERT/CC as a CNA, 0.3% affect products that JPCERT/CC develops as a vendor.

99.7%
Self-reported: 9 (0.3%)
Third-party: 3,112 (99.7%)

Of all the CVEs published that affect products developed by JPCERT/CC, 100.0% are self-published by JPCERT/CC as a CNA.

100.0%
Self-published: 9 (100.0%)
Other CNAs: 0 (0.0%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-16167CRITICAL
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Jan 9, 20199.885NOYES
CVE-2026-33277HIGH
An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.
Apr 27, 20268.837NONO
CVE-2018-16168CRITICAL
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
Jan 9, 20199.829NONO
CVE-2026-28704HIGH
Emocheck insecurely loads Dynamic Link Libraries (DLLs). If a crafted DLL file is placed to the same directory, an arbitrary code may be executed with the privilege of the user inv
Apr 10, 20267.828NONO
CVE-2018-16166HIGH
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Jan 9, 20198.826NONO
CVE-2026-33566MEDIUM
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.
Apr 27, 20264.321NONO
CVE-2018-16165MEDIUM
Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Jan 9, 20196.120NONO
CVE-2023-38752MEDIUM
Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the attribute inform
Aug 9, 20234.318NONO
CVE-2023-38751MEDIUM
Improper authorization vulnerability in Special Interest Group Network for Analysis and Liaison versions 4.4.0 to 4.7.7 allows the authorized API users to view the organization inf
Aug 9, 20234.315NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
44%
33%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (11.1%)
Network8 (88.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low3 (33.3%)
High0 (0.0%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by JPCERT/CC.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by JPCERT/CC — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For JPCERT/CC's Products

View all 1 CNAs →

Top CWEs