Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Emc Unity Operating Environment HIGH 7.8
CVE-2021-36289

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit t…

Fix: after 8.1.21.266
Fix from $1,950 2022-01-25
Network Security MEDIUM 5.5
CVE-2022-22703

In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe install…

Fix: 2.1.1 / 3.0.2+
Fix from $1,600 2022-01-17
Business One MEDIUM 5.5
CVE-2021-44234

SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos…

Mitigation only
Fix from $1,600 2022-01-14
Sterling Gentran MEDIUM 5.5
CVE-2021-39032

IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X…

Patch available
Fix from $1,600 2022-01-14
Docker Desktop MEDIUM 5.5
CVE-2021-45449

Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. Th…

Mitigation only
Fix from $1,600 2022-01-12
Cp 8000 Master Module With I\/o 25\/\+70 Firmware HIGH 7.5
CVE-2021-45034

A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al…

Fix: 16.20+
Fix from $1,950 2022-01-11
Geode HIGH 7.5
CVE-2021-34797

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with …

Fix: after 1.13.4
Fix from $1,950 2022-01-04
Emc Avamar Server MEDIUM 6.7
CVE-2021-36318

Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially explo…

Patch available
Fix from $1,600 2021-12-21
Android MEDIUM 5.5
CVE-2021-0997

In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could…

Patch available
Fix from $1,600 2021-12-15
Mattermost HIGH 7.5
CVE-2021-37861

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

Fix: after 6.0.2
Fix from $1,950 2021-12-09
Agent HIGH 7.5
CVE-2021-34800

Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147

Patch available
Fix from $1,950 2021-11-29
Emc Powerscale Onefs MEDIUM 5.5
CVE-2021-21561

Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SS…

Patch available
Fix from $1,600 2021-11-23
Ecns280 Td Firmware MEDIUM 5.5
CVE-2021-37036

There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specif…

Mitigation only
Fix from $1,600 2021-11-23
Secure Connect Gateway MEDIUM 5.5
CVE-2021-36340

Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability …

Mitigation only
Fix from $1,600 2021-11-20
Greenplum MEDIUM 6.5
CVE-2021-22030

In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information i…

Fix: 5.28.14 / 6.17.0+
Fix from $1,600 2021-11-19
Halo\+ Camera Firmware MEDIUM 6.5
CVE-2021-3791

An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on…

Fix: 03.40.00 / 03.40.02+
Fix from $1,600 2021-11-12
Simatic Pcs 7 MEDIUM 5.5
CVE-2021-40364

A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All …

Fix: 9.1+
Fix from $1,600 2021-11-09
Simatic Rtls Locating Manager MEDIUM 5.5
CVE-2020-10052

A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as …

Fix: 2.12+
Fix from $1,600 2021-11-09
GitLab MEDIUM 6.7
CVE-2021-39913

Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before…

Fix: 14.2.6 / 14.3.4+
Fix from $1,600 2021-11-05
Vigorconnect HIGH 7.5
CVE-2021-20129

An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.

No fix yet
Fix from $1,950 2021-10-13
Tor Browser MEDIUM 6.1
CVE-2021-39246

Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact…

Fix: after 10.5.6
Fix from $1,600 2021-09-24
Check Spelling CRITICAL 9.9
CVE-2021-32724

check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https:…

Fix: 0.0.19+
Fix from $2,300 2021-09-09
Nextcloud Server MEDIUM 5.5
CVE-2021-32801

Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially s…

Fix: 20.0.12 / 21.0.4+
Fix from $1,600 2021-09-07
Brave MEDIUM 6.1
CVE-2021-22929

An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connect…

Fix: 1.28.62+
Fix from $1,600 2021-08-31
Cloud Foundation HIGH 7.5
CVE-2021-22024

The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with net…

Fix: 8.5.0+
Fix from $1,950 2021-08-30
Netmodule Router Software HIGH 8.8
CVE-2021-39291

Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are …

Fix: 4.3.0.113 / 4.4.0.111+
Fix from $1,950 2021-08-23
Shopware MEDIUM 6.5
CVE-2021-37709

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log…

Fix: 6.4.3.1+
Fix from $1,600 2021-08-16
Emc Powerscale Onefs MEDIUM 5.5
CVE-2021-36278

Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious…

Fix: after 9.1.0
Fix from $1,600 2021-08-16
Emc Data Protection Search HIGH 7.8
CVE-2021-21601

Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local…

Fix: 2.7 / 19.5+
Fix from $1,950 2021-08-10
Graylog CRITICAL 9.8
CVE-2021-37759

A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID…

Fix: 4.1.2+
Fix from $2,300 2021-07-31