This page lists publicly disclosed CVE vulnerabilities affecting jpcert logontracer (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-33566 | There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered. | [email protected] | 5.1 | 0.18% | 2026-04-26 | 2026-06-17 |
| CVE-2026-33277 | An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user. | [email protected] | 8.7 | 1.21% | 2026-04-26 | 2026-06-17 |
| CVE-2018-16168 | LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors. | [email protected] | 9.8 | 2.40% | 2019-01-09 | 2026-06-16 |
| CVE-2018-16167 | LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | [email protected] | 9.8 | 74.74% | 2019-01-09 | 2026-06-16 |
| CVE-2018-16166 | LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. | [email protected] | 8.8 | 1.88% | 2019-01-09 | 2026-06-16 |
| CVE-2018-16165 | Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | [email protected] | 6.1 | 1.12% | 2019-01-09 | 2026-06-16 |