Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Fs 210 Firmware HIGH 7.5
CVE-2019-18385

An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= s…

No fix yet
Fix from $1,950 2019-10-23
Cf Deployment HIGH 8.8
CVE-2019-11283

Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volu…

Fix: 2.0.3 / 12.2.0+
Fix from $1,950 2019-10-23
Rapidgator CRITICAL 9.8
CVE-2019-17395

In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to atta…

No fix yet
Fix from $2,300 2019-10-15
Parent And Family CRITICAL 9.8
CVE-2019-17394

In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be avai…

No fix yet
Fix from $2,300 2019-10-15
Powerschool Mobile CRITICAL 9.8
CVE-2019-17396

In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available …

Fix: 1.1.8+
Fix from $2,300 2019-10-15
Dark Horse Comics CRITICAL 9.8
CVE-2019-17398

In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during auth…

No fix yet
Fix from $2,300 2019-10-15
Orbitz CRITICAL 9.8
CVE-2019-17355

In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attacke…

No fix yet
Fix from $2,300 2019-10-15
Doordash CRITICAL 9.8
CVE-2019-17397

In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available t…

Fix: after 11.5.2
Fix from $2,300 2019-10-15
Ansible Engine MEDIUM 5.5
CVE-2019-14858

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar…

Fix: after 3.5.0
Fix from $1,600 2019-10-14
Ansible Engine HIGH 7.8
CVE-2019-14846

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi…

Fix: 2.6.20 / 2.7.14+
Fix from $1,950 2019-10-08
Undertow CRITICAL 9.8
CVE-2019-10212

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o…

Fix: 2.0.20+
Fix from $2,300 2019-10-02
Big Ip Access Policy Manager HIGH 7.5
CVE-2019-6656

BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are …

Fix: 13.1.3 / 14.0.0.5+
Fix from $1,950 2019-09-25
Vcenter Server HIGH 7.7
CVE-2019-5532

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to t…

No fix yet
Fix from $1,950 2019-09-18
Rsa Identity Governance And Lifecycle HIGH 7.8
CVE-2019-3763

The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure v…

Mitigation only
Fix from $1,950 2019-09-11
Couchbase Server MEDIUM 5.3
CVE-2019-11465

An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted userna…

Fix: after 5.5.3
Fix from $1,600 2019-09-10
GitLab MEDIUM 6.5
CVE-2019-11549

An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10…

Fix: 11.8.9 / 11.9.10+
Fix from $1,600 2019-09-09
Kubernetes MEDIUM 6.5
CVE-2019-11250

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via log…

Fix: 1.15.3+
Fix from $1,600 2019-08-29
Command Centre CRITICAL 9.8
CVE-2019-15294

An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visito…

Fix: 8.10.1092+
Fix from $2,300 2019-08-28
Server MEDIUM 6.5
CVE-2019-15507

In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters…

Fix: after 2019.7.6
Fix from $1,600 2019-08-23
Server MEDIUM 6.5
CVE-2019-15508

In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables …

Fix: after 2019.7.6
Fix from $1,600 2019-08-23
Pi Web Api MEDIUM 6.5
CVE-2019-13515

OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information.

Fix: after 2018
Fix from $1,600 2019-08-15
Swwhd Intcam Hd Firmware MEDIUM 5.5
CVE-2018-20956

Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31.

No fix yet
Fix from $1,600 2019-08-08
Enterprise Network Function Virtualization Infrastructure MEDIUM 6.5
CVE-2019-1953

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a pas…

Fix: 3.9.1+
Fix from $1,600 2019-08-08
Configuration As Code MEDIUM 5.5
CVE-2019-10367

Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expec…

Fix: after 1.26
Fix from $1,600 2019-08-07
Mask Passwords MEDIUM 6.5
CVE-2019-10370

Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially…

Fix: after 2.12.0
Fix from $1,600 2019-08-07
Cpanel MEDIUM 6.5
CVE-2016-10819

In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).

Fix: 11.50.6.2 / 11.52.6.1+
Fix from $1,600 2019-08-01
Configuration As Code MEDIUM 5.5
CVE-2019-10345

Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

Fix: 1.20+
Fix from $1,600 2019-07-31
Maven MEDIUM 6.5
CVE-2019-10358

Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables…

Fix: after 3.3
Fix from $1,600 2019-07-31
Ec2 MEDIUM 5.5
CVE-2019-10364

Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log.

Fix: after 1.43
Fix from $1,600 2019-07-31
Storm HIGH 7.5
CVE-2019-0202

The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i…

Fix: after 1.2.2
Fix from $1,950 2019-07-26