Vulnerability Database

With exploit

Maven icon org.graylog2 / graylog2-server

Title Severity Exploit Date Affected Version
CVE-2025-53106 High Jun 30, 2025 >= 6.2.0 < 6.2.4
>= 6.3.0-alpha.1 < 6.3.0-rc.2
CVE-2025-46827 High May 7, 2025 < 6.0.14
>= 6.1.0 < 6.1.10
Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser High May 7, 2025 < 6.2.0
CVE-2025-30373 Medium Apr 7, 2025 >= 6.1.0 < 6.1.9
CVE-2024-24824 High Feb 7, 2024 >= 2.0.0 < 5.1.11
>= 5.2.0-alpha.1 < 5.2.4
CVE-2024-24823 Medium Feb 7, 2024 >= 4.3.0 < 5.1.11
>= 5.2.0-alpha.1 < 5.2.4
CVE-2023-41044 Low Aug 31, 2023 >= 5.1.0 < 5.1.3
CVE-2023-41045 Low Aug 31, 2023 >= 5.1.0 < 5.1.3
< 5.0.9
CVE-2023-41041 Low Aug 30, 2023 >= 1.0 < 5.0.9
>= 5.1.0 < 5.1.3
Graylog server has partial path traversal vulnerability in Support Bundle feature Low Jul 6, 2023 >= 5.1.0 < 5.1.3