Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Big Ip Domain Name System MEDIUM 5.5
CVE-2023-41253

When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Sof…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2023-10-10
Big Iq Centralized Management MEDIUM 5.5
CVE-2023-43485

When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software version…

Fix: 8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+
Fix from $1,600 2023-10-10
Subiquity MEDIUM 5.5
CVE-2023-5182

Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has…

Fix: after 23.09.1
Fix from $1,600 2023-10-07
Agent MEDIUM 5.5
CVE-2023-45241

Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before b…

Mitigation only
Fix from $1,600 2023-10-05
Ansible Automation Platform MEDIUM 6.3
CVE-2023-4380

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T…

Mitigation only
Fix from $1,600 2023-10-04
Ur5x Firmware HIGH 7.5
CVE-2023-43261EPSS 59%

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

Fix: 35.3.0.7+
Fix from $1,950 2023-10-04
Ibermatica Rps HIGH 7.5
CVE-2023-3349

Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, …

Mitigation only
Fix from $1,950 2023-10-03
Ibermatica Rps HIGH 7.5
CVE-2023-3350

A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could …

Mitigation only
Fix from $1,950 2023-10-03
Ops Center Administrator MEDIUM 5.5
CVE-2023-3335

Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensitive inf…

Fix: 10.9.3-00+
Fix from $1,600 2023-10-03
Cyber Protect HIGH 7.5
CVE-2023-44155

Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.

Fix: 15+
Fix from $1,950 2023-09-27
Emui HIGH 7.5
CVE-2023-41308

Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.

Mitigation only
Fix from $1,950 2023-09-27
Argo Cd CRITICAL 9.6
CVE-2023-40029

Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. …

Fix: 2.6.15 / 2.7.14+
Fix from $2,300 2023-09-07
Pipeline Maven Integration MEDIUM 5.3
CVE-2023-41934

Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentia…

Fix: after 1330.v18e473854496
Fix from $1,600 2023-09-06
Agent MEDIUM 5.5
CVE-2023-4688

Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433.

Mitigation only
Fix from $1,600 2023-08-31
C\+\+ HIGH 7.5
CVE-2021-32050

Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu…

Fix: 1.1.1 / 1.9.2+
Fix from $1,950 2023-08-29
Spinnaker MEDIUM 5.3
CVE-2023-39348

Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's…

Fix: 1.28.8 / 1.29.6+
Fix from $1,600 2023-08-28
Powerscale Onefs MEDIUM 6.5
CVE-2023-32491

Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could pote…

Fix: after 9.5.0.3
Fix from $1,600 2023-08-16
Cms MEDIUM 6.5
CVE-2020-24804

Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs.

Mitigation only
Fix from $1,600 2023-08-11
Mattermost HIGH 7.5
CVE-2023-4108

Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged

Fix: 7.8.8 / 7.9.6+
Fix from $1,950 2023-08-11
GitLab HIGH 7.5
CVE-2023-3993

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all…

Fix: 16.0.8 / 16.1.3+
Fix from $1,950 2023-08-02
Fabric Operating System MEDIUM 6.5
CVE-2023-31426

The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers pas…

Fix: 8.2.3d / 9.1.1c+
Fix from $1,600 2023-08-01
Isolation Segment MEDIUM 6.5
CVE-2023-20891

The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials …

Fix: 2.11.35 / 2.11.42+
Fix from $1,600 2023-07-26
Wyse Thinos MEDIUM 5.5
CVE-2023-32447

Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to th…

Fix: 9.4.2103+
Fix from $1,600 2023-07-20
Wyse Thinos MEDIUM 5.5
CVE-2023-32455

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with l…

Fix: after 9.3.2102
Fix from $1,600 2023-07-20
Wyse Thinos MEDIUM 5.5
CVE-2023-32446

Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with l…

Mitigation only
Fix from $1,600 2023-07-20
Cloud Pak For Data HIGH 7.5
CVE-2023-26023

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Cloud Pak For Data HIGH 7.5
CVE-2023-26026

Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil…

Patch available
Fix from $1,950 2023-07-19
Archer MEDIUM 5.5
CVE-2023-37224

An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the l…

Fix: 6.13.0.1+
Fix from $1,600 2023-07-14
Authentication Proxy MEDIUM 6.5
CVE-2023-20207

A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive informatio…

Mitigation only
Fix from $1,600 2023-07-12
Teamcity MEDIUM 6.5
CVE-2023-38064

In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log

Fix: 2023.05.1+
Fix from $1,600 2023-07-12