Siem
Vendor:
First CVE: Feb 3, 2024 · Active for 2 years
22
Total CVEs
More Total CVEs than 94% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Siem over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2024
2 years ago
Most Recent CVE
Nov 28, 2025
239 days ago
CVE Severity & Scoring
Siem22 CVEs
64%
32%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network14 (63.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (31.8%)
Attack Complexity
Low14 (63.6%)
High8 (36.4%)
Unknown0 (0.0%)
User Interaction
None17 (77.3%)
Unknown0 (0.0%)
Required5 (22.7%)
Privileges Required
Low11 (50.0%)
High2 (9.1%)
None9 (40.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66360HIGH An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpoint internal service (Redis) information to li-admin users. | Nov 28, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-33857CRITICAL An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access to the system can trigger Serv | May 7, 2024 | 9.6 | 25 | NO | NO |
CVE-2022-48684HIGH An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search template uses jinja templating for generating dynamic data. This co | Apr 27, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-54317HIGH An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vulnerability when creating a Layout Template, which can lead to | Jul 20, 2025 | 8.4 | 22 | NO | NO |
CVE-2024-48950HIGH An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and auth | Nov 7, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-66359MEDIUM An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multiple components leads to a cross-site scripting (XSS) vulnerabi | Nov 28, 2025 | 6.1 | 21 | NO | NO |
CVE-2024-56086HIGH An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to R | Dec 16, 2024 | 7.1 | 21 | NO | NO |
CVE-2024-48953HIGH An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed u | Nov 7, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-48951HIGH An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass. | Nov 7, 2024 | 7.5 | 21 | NO | NO |
CVE-2025-66361MEDIUM An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended period during high CPU load. | Nov 28, 2025 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Siem
Top CWEs
Versions
No cataloged versions.