Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Teamcity HIGH 7.5
CVE-2022-44624

In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters

Fix: 2022.10+
Fix from $1,950 2022-11-03
Ops Center Analyzer MEDIUM 5.5
CVE-2022-3191

Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allo…

Fix: 10.9.0-00+
Fix from $1,600 2022-11-01
Infrastructure Analytics Advisor MEDIUM 5.5
CVE-2022-41553

Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component)…

Fix: 10.9.0-00+
Fix from $1,600 2022-11-01
Nessus MEDIUM 6.5
CVE-2022-3499

An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disc…

Fix: 10.4.0+
Fix from $1,600 2022-10-31
Account MEDIUM 5.5
CVE-2022-39874

Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

Fix: 13.5.01.3+
Fix from $1,600 2022-10-07
Elastic Cloud Enterprise MEDIUM 5.3
CVE-2022-23716

A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment…

Fix: 3.1.1+
Fix from $1,600 2022-09-28
Rocket.chat MEDIUM 5.3
CVE-2022-32217

A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs.

Fix: 4.6.4+
Fix from $1,600 2022-09-23
Teamcity MEDIUM 5.3
CVE-2022-40979

In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable

Fix: 2022.04.4+
Fix from $1,600 2022-09-23
1350 Optical Management System HIGH 7.5
CVE-2022-39821

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical…

Mitigation only
Fix from $1,950 2022-09-13
Emc Powerscale Onefs HIGH 7.5
CVE-2022-34369

Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in…

Fix: after 9.4.0.3
Fix from $1,950 2022-09-02
Oneview MEDIUM 5.5
CVE-2022-28625

A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user co…

Fix: 6.60.01+
Fix from $1,600 2022-08-31
Glibc MEDIUM 5.3
CVE-2022-39046

An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads…

No fix yet
Fix from $1,600 2022-08-31
Elastic Cloud Enterprise MEDIUM 6.5
CVE-2022-23715

A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystor…

Fix: 3.4.0+
Fix from $1,600 2022-08-25
Cloud Agent MEDIUM 5.5
CVE-2022-29550

An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This ma…

No fix yet
Fix from $1,600 2022-08-18
Consul Template HIGH 7.5
CVE-2022-38149

HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.E…

Fix: 0.29.2+
Fix from $1,950 2022-08-17
Android MEDIUM 5.5
CVE-2022-20278

In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local inf…

Mitigation only
Fix from $1,600 2022-08-12
Teamcity MEDIUM 5.3
CVE-2022-38133

In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases

Fix: 2022.04.3+
Fix from $1,600 2022-08-10
Cloudvision Portal MEDIUM 5.5
CVE-2022-29071

This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai…

Fix: after 2022.1.0
Fix from $1,600 2022-08-05
Wl Wn579x3 Firmware HIGH 7.5
CVE-2022-34570

WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessin…

No fix yet
Fix from $1,950 2022-07-25
Couchbase Server HIGH 7.5
CVE-2022-32556

An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.

Fix: 7.1.1+
Fix from $1,950 2022-07-21
Teamcity MEDIUM 6.5
CVE-2022-36321

In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases

Fix: 2022.04.2+
Fix from $1,600 2022-07-20
Zxmp M721 Firmware HIGH 7.5
CVE-2022-23141

ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled,…

Mitigation only
Fix from $1,950 2022-07-15
Couchbase Server MEDIUM 5.9
CVE-2022-34826

In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.

Mitigation only
Fix from $1,600 2022-07-15
Couchbase Server MEDIUM 5.3
CVE-2022-33911

An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Un…

Fix: 7.0.4+
Fix from $1,600 2022-07-12
Hcl Launch MEDIUM 5.5
CVE-2022-27549

HCL Launch may store certain data for recurring activities in a plain text format.

Mitigation only
Fix from $1,600 2022-07-06
Openvpn Access Server HIGH 7.5
CVE-2022-33737

The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random genera…

Fix: 2.11.0+
Fix from $1,950 2022-07-06
Weave Gitops HIGH 7.5
CVE-2022-31098

Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulner…

Fix: 0.8.1+
Fix from $1,950 2022-06-27
Adaptive Security Device Manager MEDIUM 5.5
CVE-2022-20651

A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensit…

Fix: 7.17.1+
Fix from $1,600 2022-06-22
Windows 10 MEDIUM 5.5
CVE-2022-30148

Windows Desired State Configuration (DSC) Information Disclosure Vulnerability

Patch available
Fix from $1,600 2022-06-15
TYPO3 MEDIUM 6.5
CVE-2022-31047

TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal…

Fix: 7.6.57 / 8.7.47+
Fix from $1,600 2022-06-14