Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Data Domain Operating System MEDIUM 5.8
CVE-2026-46467

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 throug…

Fix: after 8.7.0.0
Fix from $1,600 2026-07-03
Opentelemetry Instrumentation For Java MEDIUM 6.5
CVE-2026-54704

OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. In versions prior to 2.28.0, t…

Fix: 2.28.0+
Fix from $1,600 2026-07-01
Devops Deploy MEDIUM 5.5
CVE-2026-12086

IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2…

Fix: 7.2.3.24 / 7.3.2.19+
Fix from $1,600 2026-06-30
Snowflake Cli MEDIUM 5.5
CVE-2026-13750

Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent l…

Fix: 3.19.0+
Fix from $1,600 2026-06-29
Traveler For Microsoft Outlook MEDIUM 5.5
CVE-2025-59868

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit applicat…

Fix: 3.0.15+
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.8
CVE-2026-9699

Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user …

Mitigation only
Fix from $1,600 2026-06-26
GitLab HIGH 7.5
CVE-2026-12053

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to…

Mitigation only
Fix from $1,950 2026-06-25
Satellite MEDIUM 6.2
CVE-2026-9073

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication …

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 5.5
CVE-2026-11819

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from …

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 6.5
CVE-2026-11820

A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod…

Mitigation only
Fix from $1,600 2026-06-23
Vllm MEDIUM 5.3
CVE-2026-54236

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize…

Fix: 0.23.1+
Fix from $1,600 2026-06-22
macOS MEDIUM 5.5
CVE-2025-46313

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Fix: 26.1+
Fix from $1,600 2026-06-11
Globalprotect MEDIUM 5.5
CVE-2026-0267

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for…

Fix: 6.2.8 / 6.3.3+
Fix from $1,600 2026-06-10
MongoDB MEDIUM 5.5
CVE-2026-9751

The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.

Fix: 7.0.35 / 8.0.24+
Fix from $1,600 2026-06-09
MongoDB MEDIUM 5.5
CVE-2026-9735

MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric …

Fix: 8.3.3+
Fix from $1,600 2026-06-09
Unclassified MEDIUM 5.5
CVE-2026-45581

fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when cha…

Mitigation only
Fix from $1,600 2026-06-08
Connect M6e 5g Firmware HIGH 8.2
CVE-2026-50205

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Mitigation only
Fix from $1,950 2026-06-04
Ebpf Instrumentation MEDIUM 6.5
CVE-2026-45679

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis e…

Fix: 0.9.0+
Fix from $1,600 2026-06-02
Unclassified HIGH 7.8
CVE-2026-40619

A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privi…

Mitigation only
Fix from $1,950 2026-06-02
Wave 7 Firmware CRITICAL 9.8
CVE-2026-49200

The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentia…

Mitigation only
Fix from $2,300 2026-05-29
Unclassified MEDIUM 5.3
CVE-2026-45040

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs.…

Mitigation only
Fix from $1,600 2026-05-28
Unclassified HIGH 7.2
CVE-2026-6720

When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded connection-configuration stru…

Patch available
Fix from $1,950 2026-05-28
Calico MEDIUM 6.5
CVE-2026-41184

In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration template uses the __SERVICEA…

Fix: 3.21.7 / 3.22.3+
Fix from $1,600 2026-05-28
Calico MEDIUM 6.5
CVE-2026-41185

When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to attach subnet information befor…

Fix: 3.21.7 / 3.22.3+
Fix from $1,600 2026-05-28
Unclassified HIGH 7.3
CVE-2026-32996

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

No fix yet
Fix from $1,950 2026-05-28
App Connect Enterprise MEDIUM 5.5
CVE-2026-5515

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.0 stores potentially sensitive information in log files that could be read by a local user.

Fix: 13.0.7.1+
Fix from $1,600 2026-05-27
Unclassified MEDIUM 5.1
CVE-2026-2607

IBM MQ Operator SC2: v3.2.0 through 3.2.23CD:  v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.…

Mitigation only
Fix from $1,600 2026-05-27
Db2 MEDIUM 5.5
CVE-2025-13755

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive infor…

Fix: after 12.1.4
Fix from $1,600 2026-05-26
Active Directory Sync HIGH 8.6
CVE-2026-25193

Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposu…

Mitigation only
Fix from $1,950 2026-05-25
Unclassified MEDIUM 6.7
CVE-2021-21508

Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerab…

Mitigation only
Fix from $1,600 2026-05-22