Siem

Vendor:

First CVE: Feb 3, 2024 · Active for 2 years

22
Total CVEs
More Total CVEs than 94% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Siem over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2024
2 years ago
Most Recent CVE
Nov 28, 2025
239 days ago

CVE Severity & Scoring

Siem22 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network14 (63.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (31.8%)
Attack Complexity
Low14 (63.6%)
High8 (36.4%)
Unknown0 (0.0%)
User Interaction
None17 (77.3%)
Unknown0 (0.0%)
Required5 (22.7%)
Privileges Required
Low11 (50.0%)
High2 (9.1%)
None9 (40.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users.
Nov 28, 20258.827NONO
An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Serv
May 7, 20249.625NONO
An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This co
Apr 27, 20248.824NONO
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to
Jul 20, 20258.422NONO
An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and auth
Nov 7, 20247.522NONO
An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerabi
Nov 28, 20256.121NONO
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to R
Dec 16, 20247.121NONO
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed u
Nov 7, 20247.521NONO
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.
Nov 7, 20247.521NONO
An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load.
Nov 28, 20256.520NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Siem

Top CWEs

Versions

No cataloged versions.