Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Solr Operator MEDIUM 6.5
CVE-2024-31391

Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Opera…

Fix: 0.8.1+
Fix from $1,600 2024-04-12
User Spam Remover HIGH 7.5
CVE-2024-31298

Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through…

Fix: 1.1+
Fix from $1,950 2024-04-10
Slideshow Gallery MEDIUM 5.3
CVE-2024-31353

Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through …

Fix: 1.7.8+
Fix from $1,600 2024-04-10
Backup And Migration HIGH 7.5
CVE-2024-31254

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration.This issue affects WordPress Backup & Migrat…

Fix: 1.4.8+
Fix from $1,950 2024-04-10
Searchiq HIGH 7.5
CVE-2024-31259

Insertion of Sensitive Information into Log File vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.5.

Fix: 4.6+
Fix from $1,950 2024-04-10
Convertkit Email Marketing\, Email Newsletter And Landing Pages HIGH 7.5
CVE-2024-31245

Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.

Fix: 2.4.6+
Fix from $1,950 2024-04-10
Fg Drupal HIGH 7.5
CVE-2024-31247

Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Drupal to WordPress.This issue affects FG Drupal to WordPress: f…

Fix: 3.71.0+
Fix from $1,950 2024-04-10
Subscribe To Comments Reloaded HIGH 7.5
CVE-2024-31249

Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Relo…

Fix: 240119+
Fix from $1,950 2024-04-10
Easy Digital Downloads MEDIUM 5.3
CVE-2024-2302

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitiv…

Fix: 3.2.10+
Fix from $1,600 2024-04-09
Db2 MEDIUM 5.5
CVE-2024-25030

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a …

Mitigation only
Fix from $1,600 2024-04-03
Unclassified MEDIUM 5.3
CVE-2024-30523

Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Mailchimp Add On pmpro-mailchimp.This i…

Mitigation only
Fix from $1,600 2024-03-31
Unclassified MEDIUM 5.3
CVE-2024-30511

Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issue affects FG PrestaShop to Wo…

Mitigation only
Fix from $1,600 2024-03-29
Unclassified MEDIUM 5.3
CVE-2024-30514

Insertion of Sensitive Information into Log File vulnerability in Paid Memberships Pro Paid Memberships Pro – Payfast Gateway Add On.This issue affec…

Mitigation only
Fix from $1,600 2024-03-29
Powerscale Onefs MEDIUM 5.5
CVE-2024-25959

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged l…

Fix: 9.4.0.17 / 9.5.0.8+
Fix from $1,600 2024-03-28
Unclassified MEDIUM 5.3
CVE-2024-25923

Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through…

Mitigation only
Fix from $1,600 2024-03-28
Unclassified MEDIUM 5.3
CVE-2024-22138

Insertion of Sensitive Information into Log File vulnerability in Seraphinite Solutions Seraphinite Accelerator.This issue affects Seraphinite Accele…

Mitigation only
Fix from $1,600 2024-03-28
Splunk HIGH 7.2
CVE-2024-29945

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation proce…

Fix: 9.0.9 / 9.1.4+
Fix from $1,950 2024-03-27
Unclassified HIGH 7.5
CVE-2023-44989

Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Co…

Mitigation only
Fix from $1,950 2024-03-26
Grab MEDIUM 5.5
CVE-2024-25957

Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. An authen…

Fix: 5.0.5+
Fix from $1,600 2024-03-26
Unclassified CRITICAL 9.9
CVE-2022-36407

Insertion of Sensitive Information into Log File vulnerability in Hitachi Virtual Storage Platform, Hitachi Virtual Storage Platform VP9500, Hitachi …

Mitigation only
Fix from $2,300 2024-03-25
Dualsafe Password Manager HIGH 7.1
CVE-2024-24272

An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentia…

Fix: 1.4.24+
Fix from $1,950 2024-03-21
Infosphere Information Server MEDIUM 5.5
CVE-2024-22352

IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 28…

Mitigation only
Fix from $1,600 2024-03-21
Unified Management Platform MEDIUM 5.5
CVE-2024-25654

Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UMP applic…

No fix yet
Fix from $1,600 2024-03-18
Ckan MEDIUM 5.3
CVE-2024-27097

A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker in…

Fix: 2.9.11 / 2.10.4+
Fix from $1,600 2024-03-13
Maximo Mobile For Eam MEDIUM 5.5
CVE-2023-43043

IBM Maximo Application Suite - Maximo Mobile for EAM 8.10 and 8.11 could disclose sensitive information to a local user. IBM X-Force ID: 266875.

Mitigation only
Fix from $1,600 2024-03-13
Worker MEDIUM 6.5
CVE-2024-28236

Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines can use variable substitution c…

Fix: 0.23.2+
Fix from $1,600 2024-03-12
Freescout HIGH 7.1
CVE-2024-28186

FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which expo…

Fix: 1.8.124+
Fix from $1,950 2024-03-12
Unclassified MEDIUM 5.6
CVE-2023-6814

Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive informa…

Mitigation only
Fix from $1,600 2024-03-12
Mq Notifier MEDIUM 6.5
CVE-2024-28154

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Fix: 1.4.1+
Fix from $1,600 2024-03-06
Linkis MEDIUM 5.3
CVE-2023-50740

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users …

Fix: 1.5.0+
Fix from $1,600 2024-03-06