Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Avantra HIGH 7.5
CVE-2026-8671

Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This …

Fix: 25.3.0+
Fix from $1,950 2026-05-22
Unclassified HIGH 7.5
CVE-2026-44052

Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files t…

Mitigation only
Fix from $1,950 2026-05-21
Splunk MEDIUM 6.5
CVE-2026-20239

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.250…

Fix: 10.0.5 / 10.0.2503.13+
Fix from $1,600 2026-05-20
Unclassified HIGH 7.6
CVE-2026-44516

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module…

Mitigation only
Fix from $1,950 2026-05-14
Vercel MEDIUM 5.5
CVE-2026-44479

Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (-…

Fix: 52.0.1+
Fix from $1,600 2026-05-13
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2026-41219

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a…

Fix: after 17.5.1
Fix from $1,600 2026-05-13
MongoDB MEDIUM 5.3
CVE-2026-8200

When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generat…

Fix: 7.0.34 / 8.0.23+
Fix from $1,600 2026-05-13
Unclassified CRITICAL 9.8
CVE-2026-43992

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate…

Patch available
Fix from $2,300 2026-05-12
Ipados HIGH 7.5
CVE-2026-28987

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequ…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Ipados HIGH 7.5
CVE-2026-28943

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequ…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
macOS HIGH 8.8
CVE-2026-28923

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A mal…

Fix: 14.8.7 / 15.7.7+
Fix from $1,950 2026-05-11
Apache Airflow Providers Opensearch MEDIUM 6.5
CVE-2026-43826

The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920…

Fix: 1.9.1+
Fix from $1,600 2026-05-11
Apache Airflow Providers Elasticsearch MEDIUM 6.5
CVE-2026-41018

The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:…

Fix: 6.5.3+
Fix from $1,600 2026-05-11
N8n Mcp MEDIUM 5.3
CVE-2026-41495

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n…

Fix: 2.47.11+
Fix from $1,600 2026-05-08
Bigfix Service Management HIGH 8.3
CVE-2024-30151

HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthoriz…

Mitigation only
Fix from $1,950 2026-05-06
Unclassified MEDIUM 5.9
CVE-2026-7824

An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadve…

Mitigation only
Fix from $1,600 2026-05-05
Unclassified HIGH 7.5
CVE-2025-67223

The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a pu…

Mitigation only
Fix from $1,950 2026-04-28
Unclassified MEDIUM 5.3
CVE-2026-41182

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of …

Mitigation only
Fix from $1,600 2026-04-23
Unclassified HIGH 8.7
CVE-2026-40945

Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in …

Mitigation only
Fix from $1,950 2026-04-21
Data Domain Operating System MEDIUM 5.7
CVE-2026-23775

Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release versi…

Fix: 8.3.1.20 / 8.6.0.0+
Fix from $1,600 2026-04-17
Powerscale Onefs MEDIUM 6.6
CVE-2025-43937

Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attac…

Fix: 9.5.1.5 / 9.7.1.10+
Fix from $1,600 2026-04-16
Airflow HIGH 7.5
CVE-2026-31987

JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that…

Fix: 3.2.0+
Fix from $1,950 2026-04-16
Unclassified HIGH 7.2
CVE-2026-20205

In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege c…

Mitigation only
Fix from $1,950 2026-04-15
Windows 10 1607 MEDIUM 5.5
CVE-2026-32217

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.9060 / 10.0.17763.8644+
Fix from $1,600 2026-04-14
Windows 10 21h2 MEDIUM 5.5
CVE-2026-32218

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.19044.7184 / 10.0.19045.7184+
Fix from $1,600 2026-04-14
Windows 10 1809 MEDIUM 5.5
CVE-2026-32215

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.17763.8644 / 10.0.19044.7184+
Fix from $1,600 2026-04-14
Unclassified HIGH 8.5
CVE-2026-0207

A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.

No fix yet
Fix from $1,950 2026-04-14
Powerchute Serial Shutdown MEDIUM 5.0
CVE-2026-2401

CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Adm…

Fix: 1.5+
Fix from $1,600 2026-04-14
Airflow HIGH 7.5
CVE-2025-66236

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to …

Fix: 3.2.0+
Fix from $1,950 2026-04-13
Tomcat HIGH 7.5
CVE-2026-34487

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet…

Fix: 9.0.117 / 10.1.54+
Fix from $1,950 2026-04-09