Securonix develops security analytics and threat detection platforms, with observed vulnerabilities concentrating in its SNYPR product around injection-class flaws and server-side request forgery weaknesses that arise in web-exposed components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Securonix over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37108HIGH An injection vulnerability in the syslog-ng configuration wizard in Securonix Snypr 6.4 allows an application user with the "Manage Ingesters" permission to execute arbitrary code | Sep 7, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-41385MEDIUM The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF. | Sep 27, 2021 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Securonix.
Media articles that mention a CVE ID that affects a product developed by Securonix — matched by CVE ID, not by vendor name.