Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Unclassified MEDIUM 5.7
CVE-2024-11165

An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. T…

Patch available
Fix from $1,600 2024-11-13
Atlantis CRITICAL 9.8
CVE-2024-52009

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (…

Fix: 0.30.0+
Fix from $2,300 2024-11-08
Authkit Nextjs MEDIUM 5.5
CVE-2024-51752

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affecte…

Fix: 0.13.2+
Fix from $1,600 2024-11-05
Emui MEDIUM 5.5
CVE-2024-51528

Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confi…

No fix yet
Fix from $1,600 2024-11-05
Unclassified MEDIUM 5.3
CVE-2024-10544

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 through …

Mitigation only
Fix from $1,600 2024-10-31
Ipados MEDIUM 5.5
CVE-2024-44239

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPadOS 17.7…

Fix: 2.1 / 11.1+
Fix from $1,600 2024-10-28
Snowflake Connector MEDIUM 5.5
CVE-2024-49750

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op…

Fix: 3.12.3+
Fix from $1,600 2024-10-24
Ipados MEDIUM 5.5
CVE-2024-44205

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and…

Fix: 12.7.6 / 13.6.8+
Fix from $1,600 2024-10-24
Rancher MEDIUM 6.5
CVE-2023-22649

A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://rancherm…

Fix: 2.6.14 / 2.7.10+
Fix from $1,600 2024-10-16
Robot Schedule MEDIUM 5.5
CVE-2024-8264

Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed loggi…

Fix: 3.05+
Fix from $1,600 2024-10-09
Expedition MEDIUM 6.5
CVE-2024-9466EPSS 13%

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern…

Fix: 1.2.96+
Fix from $1,600 2024-10-09
Unclassified MEDIUM 5.3
CVE-2024-9621

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be …

Mitigation only
Fix from $1,600 2024-10-08
Mediawiki MEDIUM 5.3
CVE-2024-47913

An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API c…

Fix: 1.39.9 / 1.41.3+
Fix from $1,600 2024-10-04
Nexus Dashboard Fabric Controller HIGH 8.6
CVE-2024-20490

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an a…

Fix: 4.2 / 4.4.1.1012+
Fix from $1,950 2024-10-02
Nexus Dashboard Fabric Controller HIGH 8.6
CVE-2024-20491

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive …

Fix: 4.2 / 4.4.1.1012+
Fix from $1,950 2024-10-02
Valeapp HIGH 7.5
CVE-2024-8609

Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information. This issue affects V…

Fix: 2.0.0+
Fix from $1,950 2024-09-27
Drive Client MEDIUM 6.5
CVE-2022-49037

Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote …

Fix: 3.3.0-15082+
Fix from $1,600 2024-09-26
Power Platform Terraform Provider HIGH 7.5
CVE-2024-47083

Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in th…

Fix: after 3.0.0
Fix from $1,950 2024-09-25
Remote Desktop Manager MEDIUM 5.5
CVE-2024-7421

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to…

Fix: 2024.3.10+
Fix from $1,600 2024-09-25
Unclassified MEDIUM 5.3
CVE-2024-43990

Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: …

No fix yet
Fix from $1,600 2024-09-25
macOS MEDIUM 5.5
CVE-2024-44166

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS…

Fix: 13.7 / 14.7+
Fix from $1,600 2024-09-17
Unclassified MEDIUM 5.5
CVE-2024-8775

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook…

Mitigation only
Fix from $1,600 2024-09-14
GitLab MEDIUM 5.5
CVE-2024-4472

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting f…

Fix: 17.1.7 / 17.2.5+
Fix from $1,600 2024-09-12
Identity Manager Rest Driver HIGH 7.5
CVE-2022-26322

Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST …

Fix: 1.1.2.0200+
Fix from $1,950 2024-09-12
Edirectory CRITICAL 9.1
CVE-2021-22533

Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

Fix: 9.2.4.0000+
Fix from $2,300 2024-09-12
Identity Manager Azuread Driver MEDIUM 5.5
CVE-2021-22518

A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all…

Fix: 5.1.4.0+
Fix from $1,600 2024-09-12
Sinema Remote Connect Client MEDIUM 5.5
CVE-2024-42344

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information…

Fix: 3.2+
Fix from $1,600 2024-09-10
Unclassified MEDIUM 5.5
CVE-2024-43781

A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection wit…

Mitigation only
Fix from $1,600 2024-09-10
Smart License Utility HIGH 7.5
CVE-2024-20440EPSS 52%

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerabili…

Mitigation only
Fix from $1,950 2024-09-04
Vault MEDIUM 6.5
CVE-2024-8365

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit devic…

Fix: 1.16.9 / 1.17.5+
Fix from $1,600 2024-09-02