Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Checkmk MEDIUM 5.5
CVE-2022-48319

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0…

Mitigation only
Fix from $1,600 2023-02-20
Db2 HIGH 7.5
CVE-2022-43930

IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log…

Patch available
Fix from $1,950 2023-02-17
Fortiportal MEDIUM 6.5
CVE-2022-43954

An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a r…

Patch available
Fix from $1,600 2023-02-16
Hong Kong Sushiro HIGH 7.5
CVE-2023-22362

SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the lo…

Mitigation only
Fix from $1,950 2023-02-13
Android MEDIUM 5.5
CVE-2023-21435

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address infor…

Mitigation only
Fix from $1,600 2023-02-09
Argo Cd MEDIUM 6.5
CVE-2023-25163

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitizatio…

Patch available
Fix from $1,600 2023-02-08
Tinacms\/cli HIGH 7.5
CVE-2023-25164

Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 w…

Fix: 1.0.9+
Fix from $1,950 2023-02-08
Syft HIGH 7.5
CVE-2023-24827

syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure f…

Patch available
Fix from $1,950 2023-02-07
Tpcms HIGH 7.5
CVE-2021-36544

Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.

No fix yet
Fix from $1,950 2023-02-03
Emc Powerscale Onefs MEDIUM 5.5
CVE-2023-22573

Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local …

Fix: 9.1.0.27 / 9.2.1.20+
Fix from $1,600 2023-02-01
Emc Powerscale Onefs HIGH 8.1
CVE-2023-22574

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A l…

Fix: 9.1.0.27 / 9.2.1.20+
Fix from $1,950 2023-02-01
Emc Powerscale Onefs HIGH 8.8
CVE-2023-22575

Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user cou…

Fix: 9.1.0.27 / 9.2.1.20+
Fix from $1,950 2023-02-01
Emc Powerscale Onefs HIGH 7.8
CVE-2023-22572

Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privile…

Fix: 9.1.0.27 / 9.2.1.20+
Fix from $1,950 2023-02-01
Emc Powerscale Onefs MEDIUM 5.5
CVE-2022-45098

Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local at…

Fix: 9.1.0.25 / 9.2.1.18+
Fix from $1,600 2023-02-01
GitLab MEDIUM 6.4
CVE-2022-3902

An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all ver…

Fix: 15.4.6 / 15.5.5+
Fix from $1,600 2023-01-26
Android MEDIUM 5.5
CVE-2022-20458

The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.ge…

Mitigation only
Fix from $1,600 2023-01-26
Shopware MEDIUM 6.5
CVE-2023-22733

Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of s…

Fix: 6.4.18.1+
Fix from $1,600 2023-01-17
Spinnaker HIGH 7.5
CVE-2022-23506

Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces mac…

Fix: 1.27.3 / 1.28.4+
Fix from $1,950 2023-01-03
M Files Server HIGH 7.5
CVE-2022-4858

Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specifi…

Fix: 22.10.11846.0+
Fix from $1,950 2022-12-30
Cognos Analytics MEDIUM 5.3
CVE-2022-43887

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys…

Fix: 11.1.7+
Fix from $1,600 2022-12-19
Pcvue MEDIUM 6.5
CVE-2022-4311

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to …

Fix: after 15.2.2
Fix from $1,600 2022-12-12
Traefik MEDIUM 6.5
CVE-2022-23469

Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displayin…

Fix: 2.9.6+
Fix from $1,600 2022-12-08
Android MEDIUM 5.5
CVE-2022-39897

Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information v…

Mitigation only
Fix from $1,600 2022-12-08
Octopus Server HIGH 7.5
CVE-2022-2721

In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in…

Fix: 2022.2.7965 / 2022.3.9163+
Fix from $1,950 2022-11-25
Media Library Assistant MEDIUM 5.3
CVE-2022-41618

Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.

Fix: 3.01+
Fix from $1,600 2022-11-18
Foundry Build2 HIGH 7.5
CVE-2022-27895

Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This …

Fix: 1.785.0+
Fix from $1,950 2022-11-15
Foundry Code Workbooks HIGH 7.5
CVE-2022-27896

Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating serv…

Fix: 4.461.0+
Fix from $1,950 2022-11-14
Mq Internet Pass Thru MEDIUM 5.5
CVE-2022-35719

IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user.

Patch available
Fix from $1,600 2022-11-14
Cyber Protect Home Office MEDIUM 5.5
CVE-2022-44745

Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107.

Fix: 40107+
Fix from $1,600 2022-11-07
Netskope HIGH 7.8
CVE-2021-44862

Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which sh…

Fix: after 91
Fix from $1,950 2022-11-03