Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Sinema Remote Connect Server HIGH 7.5
CVE-2022-32254

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST request could force the application…

Fix: 3.1+
Fix from $1,950 2022-06-14
Couchbase Server HIGH 7.5
CVE-2022-32565

An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.

Fix: 7.1.0+
Fix from $1,950 2022-06-13
Couchbase Server MEDIUM 6.5
CVE-2022-32193

Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

Fix: after 6.6.3
Fix from $1,600 2022-06-13
Account MEDIUM 5.3
CVE-2022-30733

Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number wit…

Fix: 13.2.00.6+
Fix from $1,600 2022-06-07
Appresponse MEDIUM 6.8
CVE-2021-43271

Riverbed AppResponse 11.8.0, 11.8.5, 11.8.5a, 11.9.0, 11.9.0a, 11.10.0, 11.11.0, 11.11.0a, 11.11.1, 11.11.1a, 11.11.5, and 11.11.5a (when configured …

Mitigation only
Fix from $1,600 2022-06-03
Telepresence Video Communication Server HIGH 7.1
CVE-2022-20806

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server …

Mitigation only
Fix from $1,950 2022-05-27
Telepresence Video Communication Server MEDIUM 6.5
CVE-2022-20807

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server …

Mitigation only
Fix from $1,600 2022-05-27
Telepresence Video Communication Server MEDIUM 6.5
CVE-2022-20809

Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server …

Mitigation only
Fix from $1,600 2022-05-26
Sannav MEDIUM 5.5
CVE-2022-28161

An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local att…

Fix: 2.2.0+
Fix from $1,600 2022-05-09
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2022-28859

On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh…

Mitigation only
Fix from $1,600 2022-05-05
Big Ip Access Policy Manager MEDIUM 5.5
CVE-2022-27636

On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13…

Fix: after 7.2.1
Fix from $1,600 2022-05-05
Fedora MEDIUM 5.3
CVE-2022-29869

cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid creden…

Fix: 6.15+
Fix from $1,600 2022-04-28
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2021-38939

IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains…

Fix: 7.3.3 / 7.4.3+
Fix from $1,600 2022-04-27
Go Getter MEDIUM 5.5
CVE-2022-29810

The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.

Fix: 1.5.11+
Fix from $1,600 2022-04-27
Foundry Issues MEDIUM 5.5
CVE-2022-27888

Foundry Issues service versions 2.244.0 to 2.249.0 was found to be logging in a manner that captured sensitive information (session tokens). This iss…

Fix: 2.249.1+
Fix from $1,600 2022-04-26
Cve Services HIGH 7.5
CVE-2022-24875

The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and including 1.1.1 the `org.conroller.…

Fix: after 1.1.1
Fix from $1,950 2022-04-21
Azure Sdk For .net MEDIUM 5.3
CVE-2022-26907

Azure SDK for .NET Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2022-04-15
Htcondor HIGH 8.1
CVE-2021-45103

An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S3 cloud storage that a user h…

Fix: 9.0.10 / 9.6.0+
Fix from $1,950 2022-04-06
Tpcms HIGH 7.5
CVE-2022-27442

TPCMS v3.2 allows attackers to access the ThinkPHP log directory and obtain sensitive information such as the administrator's user name and password.

No fix yet
Fix from $1,950 2022-04-04
Notebook HIGH 7.5
CVE-2022-24758

The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive …

Fix: 6.4.10+
Fix from $1,950 2022-03-31
Dvs Avilys HIGH 7.5
CVE-2022-27192

The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file download. An unauthenticated attac…

Fix: 3.5.58+
Fix from $1,950 2022-03-23
Jupyter Server HIGH 7.5
CVE-2022-24757

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, una…

Fix: 1.15.4+
Fix from $1,950 2022-03-23
Cmdbuild MEDIUM 6.5
CVE-2022-25518

In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with database access to read the pa…

Fix: after 3.3.2
Fix from $1,600 2022-03-22
Unified Threat Management HIGH 7.8
CVE-2022-0652

Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to…

Fix: 9.710+
Fix from $1,950 2022-03-22
Ansible MEDIUM 5.5
CVE-2021-20180

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…

Fix: 2.9.18+
Fix from $1,600 2022-03-16
Fedora HIGH 7.5
CVE-2022-0725

A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vuln…

Mitigation only
Fix from $1,950 2022-03-10
Climatix Pol909 Firmware MEDIUM 6.5
CVE-2021-41543

A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). Th…

Fix: 11.36 / 11.44+
Fix from $1,600 2022-03-08
Correosexpress MEDIUM 5.3
CVE-2021-25009

The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender…

Fix: after 2.6.0
Fix from $1,600 2022-03-07
Terraform Enterprise HIGH 7.5
CVE-2022-25374

HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP requests in a manner that may captu…

Fix: 202202-1+
Fix from $1,950 2022-02-25
Globalprotect MEDIUM 5.5
CVE-2022-0021

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credenti…

Fix: 5.2.9+
Fix from $1,600 2022-02-10