VendorsJPCERTlogontracerall versions
Vulnerabilities

JPCERT LogonTracer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2018-16167
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Published 2019-01-09 · Modified
10.01 PoCEPSS 0.749
CVE-2018-16168
LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.
Published 2019-01-09 · Modified
9.8EPSS 0.024
CVE-2026-33277
An OS command Injection issue exists in LogonTracer prior to v2.0.0. An arbitrary OS command may be executed by a logged-in user.
Published 2026-04-27 · Analyzed
8.8EPSS 0.023
CVE-2018-16166
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Published 2019-01-09 · Modified
8.8EPSS 0.019
CVE-2018-16165
Cross-site scripting vulnerability in LogonTracer 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2019-01-09 · Modified
6.1EPSS 0.011
CVE-2026-33566
There is a cypher injection issue in LogonTracer prior to v2.0.0. If specially crafted Windows event log data is loaded, the contents of the database may be altered.
Published 2026-04-27 · Analyzed
5.1EPSS 0.003