Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Unclassified MEDIUM 5.5
CVE-2026-75485

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, …

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.2
CVE-2026-75057

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-59911

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low pri…

Fix unknown
Fix from $4,000 2026-08-17
Storage Scale MEDIUM 5.5
CVE-2026-19483

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.5
CVE-2026-19502

MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain…

No fix yet
Fix from $4,000 2026-08-12
Db2 MEDIUM 5.5
CVE-2026-18097

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to ob…

No fix yet
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68969

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18710

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to applica…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71474

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71845

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-20708

Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information d…

No fix yet
Fix from $4,000 2026-08-11
Ranger MEDIUM 6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19363

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.4
CVE-2026-46358

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific …

No fix yet
Fix from $1,600 2026-08-05
Roomos MEDIUM 6.5
CVE-2026-20289

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive informa…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's …

No fix yet
Fix from $1,600 2026-07-31
App Connect Enterprise HIGH 7.5
CVE-2026-12947

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that coul…

Fix: 12.0.12.28 / 13.0.8.0+
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.6
CVE-2026-44105

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the lo…

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-14528

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Goland MEDIUM 5.7
CVE-2026-64800

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

Fix: 2026.2+
Fix from $1,600 2026-07-23
N8n MEDIUM 6.5
CVE-2026-65589

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secr…

Fix: 1.123.64 / 2.29.8+
Fix from $1,600 2026-07-22
Openclaw MEDIUM 5.0
CVE-2026-62211

OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust caller…

Fix: 2026.6.1+
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-46514

Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plainte…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.7
CVE-2026-15737

AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore p…

No fix yet
Fix from $1,600 2026-07-16
Powerscale Onefs MEDIUM 5.5
CVE-2026-40633

Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log F…

Fix: 9.10.1.8 / 9.13.1.0+
Fix from $1,600 2026-07-15
Windows 10 21h2 MEDIUM 5.5
CVE-2026-50316

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.19044.7548 / 10.0.19045.7548+
Fix from $1,600 2026-07-14
Unclassified CRITICAL 9.2
CVE-2026-22098

Various sensitive information such as passwords and charging card UIDs are written to log files.

Mitigation only
Fix from $2,300 2026-07-13
Hcl Devops Deploy MEDIUM 5.5
CVE-2026-56459

HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure.  The application stores potentially sensitive information in log f…

Fix: 7.3.2.19 / 8.0.1.14+
Fix from $1,600 2026-07-09
Unclassified HIGH 8.1
CVE-2026-54652

Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the…

Patch available
Fix from $1,950 2026-07-08