Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Unclassified HIGH 8.2
CVE-2024-43444

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sou…

Mitigation only
Fix from $1,950 2024-08-26
Retool MEDIUM 6.5
CVE-2024-42056

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissio…

Fix: after 3.40.0
Fix from $1,600 2024-08-22
Ai Engine HIGH 7.2
CVE-2024-6451

AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the …

Fix: 2.4.3+
Fix from $1,950 2024-08-19
Big Ip Next Central Manager MEDIUM 5.5
CVE-2024-41719

When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Centra…

Fix: 20.2.1+
Fix from $1,600 2024-08-14
Ruggedcom Rm1224 Lte\(4g\) Eu Firmware MEDIUM 6.5
CVE-2024-41978

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…

Fix: 8.1+
Fix from $1,600 2024-08-13
Smartmag HIGH 7.5
CVE-2024-37930

Insertion of Sensitive Information into Log File vulnerability in ThemeSphere SmartMag smartmag-responsive-retina-wordpress-magazine.This issue affec…

Fix: after 9.3.0
Fix from $1,950 2024-08-12
Elastic Agent MEDIUM 6.5
CVE-2024-37283

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debu…

Fix: 8.15.0+
Fix from $1,600 2024-08-12
Apm Server MEDIUM 6.5
CVE-2024-37286

APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific…

Fix: 8.14.0+
Fix from $1,600 2024-08-03
Business Automation Workflow MEDIUM 6.5
CVE-2024-38321

IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations th…

Fix: after 22.0.2
Fix from $1,600 2024-08-03
Fogproject MEDIUM 5.3
CVE-2024-42349

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via log…

Fix: 1.5.10.47+
Fix from $1,600 2024-08-02
Ctt Expresso Para Woocommerce HIGH 7.5
CVE-2024-6687

The CTT Expresso para WooCommerce plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 3.2.12 via…

Fix: 3.2.13+
Fix from $1,950 2024-08-01
Cato Client MEDIUM 6.5
CVE-2024-6977

A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account …

Fix: after 5.10.34
Fix from $1,600 2024-07-31
Elasticsearch MEDIUM 6.5
CVE-2023-49921

An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents o…

Fix: 7.17.16 / 8.11.2+
Fix from $1,600 2024-07-26
Arrow HIGH 7.5
CVE-2024-41178

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using…

Fix: after 0.10.1
Fix from $1,950 2024-07-23
Teamcity MEDIUM 6.5
CVE-2024-41824

In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases

Fix: 2024.07+
Fix from $1,600 2024-07-22
Unclassified MEDIUM 5.4
CVE-2024-0006

Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs to obtain database user creden…

Patch available
Fix from $1,600 2024-07-19
Unclassified MEDIUM 5.3
CVE-2024-40636

Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using ex…

Mitigation only
Fix from $1,600 2024-07-17
Junos MEDIUM 6.3
CVE-2024-39532

An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allows a local, authenticated att…

Fix: 21.2+
Fix from $1,600 2024-07-11
Unclassified MEDIUM 5.3
CVE-2024-37205

Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.…

No fix yet
Fix from $1,600 2024-07-10
Unclassified MEDIUM 5.3
CVE-2024-37270

Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a b…

Mitigation only
Fix from $1,600 2024-07-10
Fortiaiops MEDIUM 6.5
CVE-2024-27784

Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an auth…

Mitigation only
Fix from $1,600 2024-07-09
Rtsper MEDIUM 5.5
CVE-2022-25477

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUe…

Fix: 10.0.22000.21355 / 10.0.22000.31274+
Fix from $1,600 2024-07-02
Unclassified MEDIUM 6.8
CVE-2024-32757

Under certain circumstances unnecessary user details are provided within system logs

No fix yet
Fix from $1,600 2024-07-02
Unclassified MEDIUM 5.3
CVE-2024-22276

VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicious actor with adjacent access…

Mitigation only
Fix from $1,600 2024-06-27
Security Verify Access MEDIUM 5.5
CVE-2023-30430

IBM Security Verify Access 10.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information from trace logs. IBM X-Force ID: 252183.

Fix: after 10.0.7.1
Fix from $1,600 2024-06-27
Fabric Operating System MEDIUM 5.5
CVE-2024-29954

A vulnerability in a password management API in Brocade Fabric OS versions before v9.2.1, v9.2.0b, v9.1.1d, and v8.2.3e prints sensitive information …

Fix: 8.2.3e / 9.1.1d+
Fix from $1,600 2024-06-26
Unclassified CRITICAL 9.3
CVE-2024-6060

An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests tha…

Mitigation only
Fix from $2,300 2024-06-25
Retryablehttp MEDIUM 5.5
CVE-2024-6104

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP b…

Fix: 0.7.7+
Fix from $1,600 2024-06-24
Wp 2fa HIGH 7.5
CVE-2022-44587

Insertion of Sensitive Information into Log File vulnerability in WP 2FA allows Accessing Functionality Not Properly Constrained by ACLs.This issue a…

Fix: 2.6.4+
Fix from $1,950 2024-06-21
Sonarqube MEDIUM 6.5
CVE-2024-38460

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part…

Fix: 9.9.4 / 10.4+
Fix from $1,600 2024-06-16