Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Stealth HIGH 7.5
CVE-2024-23758

An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file.

Mitigation only
Fix from $1,950 2024-02-20
Cloud Pak For Security MEDIUM 5.5
CVE-2024-22335

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in lo…

Fix: 1.10.18.0+
Fix from $1,600 2024-02-17
Cloud Pak For Security MEDIUM 5.5
CVE-2024-22336

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in lo…

Fix: 1.10.18.0+
Fix from $1,600 2024-02-17
Cloud Pak For Security MEDIUM 5.5
CVE-2024-22337

IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentially sensitive information in lo…

Fix: 1.10.18.0+
Fix from $1,600 2024-02-17
Passportal HIGH 7.5
CVE-2023-47131

The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

Fix: 3.29.2+
Fix from $1,950 2024-02-08
Emc Appsync MEDIUM 6.8
CVE-2024-22464

Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitive information vulnerability in…

Fix: 4.6.0.2+
Fix from $1,600 2024-02-08
Apm Server HIGH 7.5
CVE-2024-23448

An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and t…

Fix: 8.12.1+
Fix from $1,950 2024-02-07
Rider MEDIUM 5.3
CVE-2024-24939

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

Fix: 2023.3.3+
Fix from $1,600 2024-02-06
Delmia Apriso HIGH 7.5
CVE-2024-0935

Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024

Fix: after 2024
Fix from $1,950 2024-02-01
Vault MEDIUM 6.5
CVE-2024-0831

Vault and Vault Enterprise (“Vault”) may expose sensitive information when enabling an audit device which specifies the `log_raw` option, which may l…

Fix: 1.15.5+
Fix from $1,600 2024-02-01
Goreleaser MEDIUM 5.5
CVE-2024-23840

GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser rel…

Patch available
Fix from $1,600 2024-01-30
Add On Builder HIGH 7.2
CVE-2023-46231

In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on …

Fix: 4.1.4+
Fix from $1,950 2024-01-30
Otrs HIGH 7.5
CVE-2024-23791

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issu…

Fix: 7.0.49 / 2024.1.1+
Fix from $1,950 2024-01-29
Airflow MEDIUM 6.5
CVE-2023-51702

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes th…

Fix: 2.6.1 / 7.0.0+
Fix from $1,600 2024-01-24
Ipados MEDIUM 5.5
CVE-2023-42937

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2…

Fix: 10.2 / 12.7.3+
Fix from $1,600 2024-01-23
Cloud MEDIUM 5.3
CVE-2024-23677

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

Fix: 9.0.8 / 9.0.2208+
Fix from $1,600 2024-01-22
Dependency Check MEDIUM 5.3
CVE-2024-23686

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an att…

Fix: 9.0.6+
Fix from $1,600 2024-01-19
Smart S150 Firmware MEDIUM 5.3
CVE-2024-0716

A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file…

No fix yet
Fix from $1,600 2024-01-19
Dormitory Management System HIGH 7.5
CVE-2024-0472

A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown process…

Mitigation only
Fix from $1,950 2024-01-12
Wp Optin Wheel HIGH 7.5
CVE-2023-51408

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for Wor…

Fix: after 1.4.3
Fix from $1,950 2024-01-08
Defender Security HIGH 7.5
CVE-2023-51490

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.T…

Fix: after 4.1.0
Fix from $1,950 2024-01-08
Database Cleaner HIGH 7.5
CVE-2023-51508

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects …

Fix: after 0.9.8
Fix from $1,950 2024-01-08
Wp Stripe Checkout HIGH 7.5
CVE-2023-52143

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a…

Fix: after 1.2.2.37
Fix from $1,950 2024-01-05
404 Solution MEDIUM 5.3
CVE-2023-52146

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.…

Fix: after 2.33.0
Fix from $1,600 2024-01-05
Cubefs MEDIUM 6.5
CVE-2023-46742

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the l…

Fix: 3.3.1+
Fix from $1,600 2024-01-03
Laf MEDIUM 6.5
CVE-2023-50253

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container witho…

Patch available
Fix from $1,600 2024-01-03
Payhere Payment Gateway HIGH 7.5
CVE-2023-6064

The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when …

Fix: 2.2.12+
Fix from $1,950 2024-01-01
Enterprise Server MEDIUM 5.7
CVE-2023-6746

An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server back-end service tha…

Fix: 3.7.19 / 3.8.12+
Fix from $1,600 2023-12-21
Enterprise Server MEDIUM 6.5
CVE-2023-6802

An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could allow an attacker to g…

Fix: 3.8.12 / 3.9.7+
Fix from $1,600 2023-12-21
Octopus Server HIGH 7.5
CVE-2023-1904

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Ser…

Fix: 2023.1.11942 / 2023.2.13151+
Fix from $1,950 2023-12-14