Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Nextcloud Server MEDIUM 5.3
CVE-2018-3776

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

Fix: 11.0.5 / 12.0.3+
Fix from $1,600 2018-08-12
Linux Kernel MEDIUM 5.5
CVE-2018-7754

The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address …

Fix: after 4.15
Fix from $1,600 2018-08-10
Ssh Agent MEDIUM 6.5
CVE-2018-1999036

An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the…

Fix: after 1.15
Fix from $1,600 2018-08-01
Openstack MEDIUM 5.5
CVE-2017-2621

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improp…

Fix: 8.0.0+
Fix from $1,600 2018-07-27
Virtualization MEDIUM 6.6
CVE-2017-15113

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change th…

Fix: 4.1.7.6+
Fix from $1,600 2018-07-27
Horizon View Agents HIGH 7.8
CVE-2018-6971

VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vm…

Fix: 7.5.1+
Fix from $1,950 2018-07-25
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-11716EPSS 14%

An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Cent…

Fix: 100230+
Fix from $2,300 2018-07-16
Manageengine Desktop Central CRITICAL 9.8
CVE-2018-11717EPSS 9%

An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obta…

Fix: 100251+
Fix from $2,300 2018-07-16
Contrail Service Orchestration CRITICAL 9.8
CVE-2018-0042

Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability.

Fix: 4.0.0+
Fix from $2,300 2018-07-11
Moodle MEDIUM 5.3
CVE-2018-10889

A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details o…

Fix: 3.3.7 / 3.4.4+
Fix from $1,600 2018-07-10
Ansible Engine MEDIUM 5.9
CVE-2018-10855

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect…

Fix: 2.4.5+
Fix from $1,600 2018-07-03
Enterprise Virtualization Manager CRITICAL 9.8
CVE-2018-1072

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option…

Fix: 4.2.2+
Fix from $2,300 2018-06-26
Solutions Business Manager MEDIUM 6.5
CVE-2018-7682

Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.

Fix: 11.4+
Fix from $1,600 2018-06-22
Solutions Business Manager HIGH 7.5
CVE-2018-7683

Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files.

Fix: 11.4+
Fix from $1,950 2018-06-21
Greencms HIGH 7.5
CVE-2018-12604EPSS 13%

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

No fix yet
Fix from $1,950 2018-06-20
Enterprise Virtualization CRITICAL 9.8
CVE-2018-1117

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou…

Fix: 1.0.6+
Fix from $2,300 2018-06-20
Ovirt HIGH 7.8
CVE-2018-1075

ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo…

Fix: 4.2.3+
Fix from $1,950 2018-06-12
Prime Collaboration HIGH 7.8
CVE-2018-0335

A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to …

Mitigation only
Fix from $1,950 2018-06-07
Grunt Gh Pages HIGH 8.6
CVE-2016-10526

A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of th…

Fix: 0.9.1+
Fix from $1,950 2018-05-31
Recoverpoint HIGH 8.8
CVE-2018-1241

Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in…

Fix: 5.1.1.3 / 5.1.2+
Fix from $1,950 2018-05-29
Octopus Server CRITICAL 9.8
CVE-2018-11320

In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deploy…

Fix: after 2018.5.1
Fix from $2,300 2018-05-21
Ubuntu Linux MEDIUM 5.5
CVE-2017-2592

python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could in…

Fix: after 3.23.0
Fix from $1,600 2018-05-08
Wp Security Audit Log MEDIUM 5.3
CVE-2018-8719EPSS 16%

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not re…

No fix yet
Fix from $1,600 2018-04-04
Logstash MEDIUM 6.5
CVE-2018-3817

When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

Fix: 5.6.6 / 6.1.2+
Fix from $1,600 2018-03-30
Pivotal Software Mysql CRITICAL 10.0
CVE-2016-0898

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup c…

Mitigation only
Fix from $2,300 2018-03-29
Identity Manager MEDIUM 5.3
CVE-2018-1349

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

Fix: after 4.6
Fix from $1,600 2018-03-26
Identity Manager MEDIUM 5.3
CVE-2018-1350

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

Fix: after 4.6
Fix from $1,600 2018-03-26
Ios Keychain CRITICAL 9.8
CVE-2018-1000123

Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Fi…

Fix: after 2.0.0
Fix from $2,300 2018-03-13
Django Anymail HIGH 7.4
CVE-2018-1000089

Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can resu…

Fix: after 1.3
Fix from $1,950 2018-03-13
File Manager HIGH 7.5
CVE-2018-7204

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manage…

Fix: after 5.0.0
Fix from $1,950 2018-03-07