NXLog develops a focused line of log-aggregation and event-forwarding products, including NXLog Manager and the core NXLog agent, deployed across environments requiring centralized visibility and compliance logging. The durable signal centers on web-tier and deserialization vulnerabilities—cross-site request forgery, cross-site scripting, and untrusted deserialization—reflecting the challenges of secure log ingestion and web-based administration interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nxlog over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35488HIGH The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the | Jan 5, 2021 | 7.5 | 31 | NO | YES |
CVE-2023-32791MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to manipulate and delete user accounts within the platform | Oct 3, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-32790MEDIUM Cross-Site Scripting (XSS) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to inject a malicious JavaScript payload into the 'Full Name' fiel | Oct 3, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-32792MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to eliminate roles within the platform by sending a specifi | Oct 3, 2023 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nxlog.
Media articles that mention a CVE ID that affects a product developed by Nxlog — matched by CVE ID, not by vendor name.