Secuavail maintains a narrow, focused product portfolio centered on the Logstare Collector, a log aggregation and security monitoring tool deployed in enterprise environments. The vendor's vulnerability surface is characterized by application-layer weaknesses endemic to web-facing management interfaces, including cross-site request forgery, cross-site scripting, improper authorization controls, and insecure default configurations, alongside instances where sensitive information has been exposed in transit or logs. Defenders should apply security controls around access to the Logstare Collector's administrative interface and ensure proper credential and secret management; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Secuavail over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64695HIGH Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be executed with the privilege of the user invo | Nov 21, 2025 | 7.8 | 26 | NO | NO |
CVE-2025-58097HIGH The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative user may manipulate files within the installation directory a | Nov 21, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-62687MEDIUM Cross-site request forgery vulnerability exists in LogStare Collector. If a user views a crafted page while logged, unintended operations may be performed. | Nov 21, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-61949MEDIUM LogStare Collector contains a stored cross-site scripting vulnerability in UserManagement. If crafted user information is stored, an arbitrary script may be executed on the web bro | Nov 21, 2025 | 5.4 | 19 | NO | NO |
CVE-2025-62189MEDIUM LogStare Collector contains an incorrect authorization vulnerability in UserRegistration. If exploited, a non-administrative user may create a new user account by sending a crafted | Nov 21, 2025 | 4.3 | 17 | NO | NO |
LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. | Nov 21, 2025 | 2.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Secuavail.
Media articles that mention a CVE ID that affects a product developed by Secuavail — matched by CVE ID, not by vendor name.