Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Graylog CRITICAL 9.8
CVE-2021-37760

A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID).

Fix: 4.1.2+
Fix from $2,300 2021-07-31
Emc Networker MEDIUM 5.5
CVE-2021-21546

Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local low-privil…

Fix: 19.3.0.4+
Fix from $1,600 2021-07-29
Impala HIGH 7.5
CVE-2021-28131

Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala lo…

Fix: 4.0.0+
Fix from $1,950 2021-07-22
Cx2 Firmware HIGH 7.5
CVE-2020-21933

An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log …

No fix yet
Fix from $1,950 2021-07-21
Idce HIGH 7.5
CVE-2020-23284

Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application …

Mitigation only
Fix from $1,950 2021-07-20
TYPO3 MEDIUM 6.5
CVE-2021-32767

TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0,…

Fix: after 11.3.0
Fix from $1,600 2021-07-20
Remotepc MEDIUM 5.5
CVE-2021-34689

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-…

Fix: 7.6.48+
Fix from $1,600 2021-07-15
Myfax150 Firmware MEDIUM 6.5
CVE-2020-24038

myFax version 229 logs sensitive information in the export log module which allows any user to access critical information.

No fix yet
Fix from $1,600 2021-07-07
Zammad HIGH 7.5
CVE-2021-35299

Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing.

Fix: after 4.0.0
Fix from $1,950 2021-06-28
Galaxy Watch Plugin MEDIUM 5.5
CVE-2021-25420

Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi pass…

Fix: 2.2.05.21033151+
Fix from $1,600 2021-06-11
Galaxy Watch 3 Plugin MEDIUM 5.5
CVE-2021-25421

Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi pas…

Fix: 2.2.09.21033151+
Fix from $1,600 2021-06-11
Watch Active Plugin MEDIUM 5.5
CVE-2021-25422

Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi pass…

Fix: 2.2.07.21033151+
Fix from $1,600 2021-06-11
Watch Active2 Plugin MEDIUM 5.5
CVE-2021-25423

Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi pas…

Fix: 2.2.08.21033151+
Fix from $1,600 2021-06-11
Sannav HIGH 7.5
CVE-2020-15380

Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level.

Fix: 2.1.1+
Fix from $1,950 2021-06-09
Secure Api Manager HIGH 7.5
CVE-2021-22516

Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulner…

No fix yet
Fix from $1,950 2021-06-04
Ansible MEDIUM 5.5
CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when usi…

Fix: 1.2.2 / 1.3.2+
Fix from $1,600 2021-05-26
Ansible MEDIUM 5.5
CVE-2021-20178

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…

Fix: 2.9.18+
Fix from $1,600 2021-05-26
Remedy Mid Tier MEDIUM 5.3
CVE-2017-17675

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack …

Mitigation only
Fix from $1,600 2021-05-19
Noobaa Operator HIGH 8.8
CVE-2021-3528

A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake…

Fix: 5.7.0+
Fix from $1,950 2021-05-13
Vault Action HIGH 7.5
CVE-2021-32074

HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line se…

Fix: 2.2.0+
Fix from $1,950 2021-05-07
Spectrum Protect Plus MEDIUM 6.2
CVE-2021-20536

IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us…

Mitigation only
Fix from $1,600 2021-04-26
Fortiadc MEDIUM 6.5
CVE-2021-24024

A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and …

Fix: after 5.3.7
Fix from $1,600 2021-04-12
Devolutions Server HIGH 7.5
CVE-2021-23924

An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

Fix: 2020.3+
Fix from $1,950 2021-04-01
Ansible MEDIUM 5.5
CVE-2021-3447

A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod…

Fix: 1.2.2 / 3.8.2+
Fix from $1,600 2021-04-01
GitLab MEDIUM 5.5
CVE-2021-22184

An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that …

Fix: 13.6.6 / 13.7.6+
Fix from $1,600 2021-03-26
Ios Xe HIGH 7.8
CVE-2021-1442

A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker t…

Mitigation only
Fix from $1,950 2021-03-24
Data Engineering MEDIUM 6.5
CVE-2021-3167

In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.

Mitigation only
Fix from $1,600 2021-03-15
Cortex Xsoar MEDIUM 5.1
CVE-2021-3034

An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO)…

Mitigation only
Fix from $1,600 2021-03-10
Vagrant MEDIUM 6.5
CVE-2021-21361

The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment …

Fix: 0.6 / 3.0.0+
Fix from $1,600 2021-03-09
Pcoip Graphics Agent MEDIUM 5.5
CVE-2021-25688

Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21.01.0 may…

Fix: 20.10.0 / 21.01.0+
Fix from $1,600 2021-02-11