Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Cloud Pak For Automation MEDIUM 6.5
CVE-2021-20359

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in lo…

Mitigation only
Fix from $1,600 2021-02-08
Emergency Responder MEDIUM 6.5
CVE-2021-1226

A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Editi…

Fix: 11.5 / 12.0+
Fix from $1,600 2021-01-13
Emc Unity Operating Environment MEDIUM 6.7
CVE-2020-26199

Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.0.4.0.5.012 contain a plain-text password storage vulnerability. A user credentials (inclu…

Fix: 5.0.4.0.5.012+
Fix from $1,600 2021-01-05
Easy Wp Smtp HIGH 7.5
CVE-2020-35234EPSS 65%

The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker c…

Fix: 1.4.4+
Fix from $1,950 2020-12-14
Kubernetes MEDIUM 5.5
CVE-2020-8563

In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the clo…

Fix: 1.19.3+
Fix from $1,600 2020-12-07
Kubernetes MEDIUM 5.5
CVE-2020-8564

In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker confi…

Fix: 1.17.13 / 1.18.10+
Fix from $1,600 2020-12-07
Kubernetes MEDIUM 5.5
CVE-2020-8565

In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API se…

Fix: after 1.19.3
Fix from $1,600 2020-12-07
Kubernetes MEDIUM 5.5
CVE-2020-8566

In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This…

Fix: 1.17.13 / 1.18.10+
Fix from $1,600 2020-12-07
Business Automation Workflow MEDIUM 5.5
CVE-2020-4900

IBM Business Automation Workflow 19.0.0.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 1…

Patch available
Fix from $1,600 2020-11-30
Wildfly MEDIUM 5.3
CVE-2020-25640

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser…

Fix: 21.0.0+
Fix from $1,600 2020-11-24
Gluster Block MEDIUM 5.5
CVE-2020-10762

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …

Fix: 0.5.1+
Fix from $1,600 2020-11-24
Gluster Storage MEDIUM 5.5
CVE-2020-10763

An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t…

Fix: 10.1.0+
Fix from $1,600 2020-11-24
Sterling B2b Integrator MEDIUM 6.5
CVE-2020-4671

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log file…

Fix: after 6.0.3.2
Fix from $1,600 2020-11-16
Gatemanager 9250 Firmware MEDIUM 6.5
CVE-2020-11643

An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows auth…

Fix: 9.0.20262 / 9.2.620236042+
Fix from $1,600 2020-10-15
Emc Openmanage Integration For Microsoft System Center MEDIUM 6.5
CVE-2020-5389

Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vu…

Fix: 7.2.1+
Fix from $1,600 2020-10-08
Android HIGH 7.5
CVE-2020-26605

An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive infor…

Mitigation only
Fix from $1,950 2020-10-06
Monocms HIGH 7.5
CVE-2020-25987

MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 c…

No fix yet
Fix from $1,950 2020-10-06
Nifi HIGH 7.5
CVE-2020-9486

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was tr…

Fix: after 1.11.4
Fix from $1,950 2020-10-01
Fabric Operating System MEDIUM 6.5
CVE-2020-15370

Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The v…

Fix: 7.4.2g+
Fix from $1,600 2020-09-25
Ansible Engine MEDIUM 5.5
CVE-2020-14330

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json o…

Fix: 2.9.12+
Fix from $1,600 2020-09-11
Ansible Engine MEDIUM 5.5
CVE-2020-14332

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive dat…

Fix: 2.8.14 / 2.9.12+
Fix from $1,600 2020-09-11
Octopus Deploy HIGH 7.5
CVE-2020-24566

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure…

Fix: 2020.3.4+
Fix from $1,950 2020-09-09
Android MEDIUM 5.5
CVE-2020-25046

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logg…

Mitigation only
Fix from $1,600 2020-08-31
Dreammapper MEDIUM 5.3
CVE-2020-14518

Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.

Fix: after 2.24
Fix from $1,600 2020-08-21
Content Security Management Appliance MEDIUM 6.5
CVE-2020-3447

A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Applianc…

Fix: 13.5.1 / 13.6.1-201+
Fix from $1,600 2020-08-17
Adaptive Server Enterprise HIGH 7.8
CVE-2020-6295

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential informat…

Mitigation only
Fix from $1,950 2020-08-12
Teamcity MEDIUM 5.3
CVE-2020-15829

In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

Fix: 2019.2.3+
Fix from $1,600 2020-08-08
Tanzu Application Service For Virtual Machines MEDIUM 5.7
CVE-2020-5414

VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains…

Fix: 2.7.15 / 2.7.19+
Fix from $1,600 2020-07-31
Tableau Server HIGH 7.5
CVE-2020-6938

A sensitive information disclosure vulnerability in Tableau Server 10.5, 2018.x, 2019.x, 2020.x released before June 26, 2020, could allow access to …

Fix: after 2020.2
Fix from $1,950 2020-07-08
Android MEDIUM 5.3
CVE-2020-15581

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The kernel logging feature allows attackers to discover …

Mitigation only
Fix from $1,600 2020-07-07