Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Unclassified MEDIUM 6.8
CVE-2024-27157

The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypa…

No fix yet
Fix from $1,600 2024-06-14
Unclassified MEDIUM 6.8
CVE-2024-27156

The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can …

Mitigation only
Fix from $1,600 2024-06-14
Unclassified MEDIUM 6.2
CVE-2024-27154

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

Mitigation only
Fix from $1,600 2024-06-14
Globalprotect HIGH 7.5
CVE-2024-5908

A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, i…

Fix: 5.1.12 / 6.0.8+
Fix from $1,950 2024-06-12
Unclassified MEDIUM 5.3
CVE-2024-32811

Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shippin…

Mitigation only
Fix from $1,600 2024-06-09
Easy Forms For Mailchimp HIGH 7.5
CVE-2024-25095

Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: …

Fix: after 6.9.0
Fix from $1,950 2024-06-04
Unclassified HIGH 7.5
CVE-2024-36127

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability…

Patch available
Fix from $1,950 2024-06-03
Unclassified MEDIUM 5.3
CVE-2024-34798

Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: fr…

No fix yet
Fix from $1,600 2024-06-03
Unclassified MEDIUM 5.1
CVE-2024-31216

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3…

Patch available
Fix from $1,600 2024-05-15
Unclassified MEDIUM 6.5
CVE-2024-3744

A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These to…

Mitigation only
Fix from $1,600 2024-05-15
Unclassified CRITICAL 9.8
CVE-2024-34706

Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is expose…

Patch available
Fix from $2,300 2024-05-14
Unclassified HIGH 7.5
CVE-2024-34559

Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0.

Mitigation only
Fix from $1,950 2024-05-14
Unclassified MEDIUM 5.3
CVE-2024-34550

Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from…

Mitigation only
Fix from $1,600 2024-05-14
Unclassified MEDIUM 5.5
CVE-2024-34353

The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Ma…

Patch available
Fix from $1,600 2024-05-14
Watson Cp4d Data Stores MEDIUM 5.5
CVE-2023-40694

IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Forc…

Fix: 4.8.5+
Fix from $1,600 2024-05-07
Unclassified HIGH 7.5
CVE-2024-34527

spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.

Mitigation only
Fix from $1,950 2024-05-06
Unclassified MEDIUM 5.3
CVE-2024-33922

Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Media Cleaner: from n/a through 6…

Mitigation only
Fix from $1,600 2024-05-02
Vault MEDIUM 5.5
CVE-2024-2877

Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby…

Fix: 1.15.8+
Fix from $1,600 2024-04-30
Unclassified HIGH 7.5
CVE-2024-33637

Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through …

Mitigation only
Fix from $1,950 2024-04-29
Unclassified HIGH 7.5
CVE-2024-32953

Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.

Mitigation only
Fix from $1,950 2024-04-24
Unclassified MEDIUM 5.3
CVE-2024-32788

Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: f…

No fix yet
Fix from $1,600 2024-04-24
Unclassified MEDIUM 6.5
CVE-2024-32051

Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent…

Mitigation only
Fix from $1,600 2024-04-24
Aspera Faspex MEDIUM 5.5
CVE-2023-22869

IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244…

Fix: 5.0.8+
Fix from $1,600 2024-04-19
Brocade Sannav HIGH 8.6
CVE-2024-29959

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's …

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav HIGH 7.5
CVE-2024-29957

When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. Thi…

Fix: 2.3.0a+
Fix from $1,950 2024-04-19
Brocade Sannav MEDIUM 6.5
CVE-2024-29958

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to re…

Fix: 2.3.0a+
Fix from $1,600 2024-04-19
Unclassified MEDIUM 5.3
CVE-2024-32686

Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3.

No fix yet
Fix from $1,600 2024-04-18
Brocade Sannav MEDIUM 5.5
CVE-2024-29955

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup log…

Fix: 2.3.0a+
Fix from $1,600 2024-04-17
Unclassified MEDIUM 5.3
CVE-2024-32513

Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO fo…

Mitigation only
Fix from $1,600 2024-04-17
Unclassified MEDIUM 6.8
CVE-2024-22440

A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability could cause disclosure of sensi…

No fix yet
Fix from $1,600 2024-04-17