Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Security HIGH 7.5
CVE-2018-7433

The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

Fix: after 6.9.0
Fix from $1,950 2018-03-02
Identity Manager CRITICAL 9.8
CVE-2017-7434

In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exceptio…

Fix: 4.6+
Fix from $2,300 2018-03-02
Identity Manager CRITICAL 9.8
CVE-2017-9278

The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this …

Fix: 4.0.2.0+
Fix from $2,300 2018-03-02
Interscan Messaging Security Virtual Appliance HIGH 8.1
CVE-2018-3609EPSS 21%

A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t…

No fix yet
Fix from $1,950 2018-02-16
Hana Extended Application Services MEDIUM 6.5
CVE-2018-2372

A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL…

Mitigation only
Fix from $1,600 2018-02-14
Sensu Core CRITICAL 9.8
CVE-2018-1000060

Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utili…

Fix: 1.2.1+
Fix from $2,300 2018-02-09
Ovirt Hosted Engine Setup HIGH 7.8
CVE-2018-1000018

An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.

Fix: 2.2.7+
Fix from $1,950 2018-01-24
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2017-6139

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client reque…

Mitigation only
Fix from $1,600 2017-12-21
Emc Scaleio HIGH 8.4
CVE-2017-8001

An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who …

Mitigation only
Fix from $1,950 2017-11-28
Ansible CRITICAL 9.8
CVE-2017-7550

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attac…

Fix: 2.3.3 / 2.4.1+
Fix from $2,300 2017-11-21
Mahara Mobile CRITICAL 9.8
CVE-2017-1000171

Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.

Fix: after 1.2.0
Fix from $2,300 2017-11-03
Ndoc CRITICAL 9.8
CVE-2017-15366

Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is…

Fix: after 7.4
Fix from $2,300 2017-10-26
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2017-6165

In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1…

Mitigation only
Fix from $2,300 2017-10-20
Debian Linux HIGH 7.5
CVE-2017-15572

In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, b…

Fix: after 3.2.5
Fix from $1,950 2017-10-18
Tor MEDIUM 5.9
CVE-2017-0380

The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x bef…

Fix: after 0.2.8.14
Fix from $1,600 2017-09-18
Heinekingmedia MEDIUM 6.5
CVE-2017-11134

An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence,…

Fix: after 1.7.5
Fix from $1,600 2017-08-01
Rsyslog MEDIUM 5.5
CVE-2015-3243

rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron.

Mitigation only
Fix from $1,600 2017-07-25
Ultra Services Framework CRITICAL 9.8
CVE-2017-6709

A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c…

Fix: after 5.0.2
Fix from $2,300 2017-07-06
Moneyworks CRITICAL 9.8
CVE-2017-9615

Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging…

Fix: after 8.0.3
Fix from $2,300 2017-06-26
Integrated Management Module Firmware MEDIUM 6.5
CVE-2017-3744

In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture …

Fix: after 6.19
Fix from $1,600 2017-06-20
Output Plugin MEDIUM 6.5
CVE-2016-10362

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

Fix: after 5.0.0
Fix from $1,600 2017-06-16
Cloud Foundry Elastic Runtime CRITICAL 9.8
CVE-2017-4955

An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28…

Mitigation only
Fix from $2,300 2017-06-13
Cordova HIGH 7.5
CVE-2016-6799

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d()…

Fix: after 5.2.2
Fix from $1,950 2017-05-09
Tl Sg108e Firmware CRITICAL 9.8
CVE-2017-8074

On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. Thi…

No fix yet
Fix from $2,300 2017-04-23
Tl Sg108e Firmware CRITICAL 9.8
CVE-2017-8075

On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affect…

No fix yet
Fix from $2,300 2017-04-23
Nova CRITICAL 9.8
CVE-2017-7214

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notificat…

Patch available
Fix from $2,300 2017-03-21
Cognos Business Intelligence MEDIUM 5.5
CVE-2016-9985

IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.

Patch available
Fix from $1,600 2017-03-08
Xclarity Administrator CRITICAL 9.8
CVE-2016-8233

Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form…

Fix: after 1.2.1
Fix from $2,300 2017-03-01
Pi Coresight HIGH 7.8
CVE-2017-5153

An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 i…

Fix: after 2016-r2
Fix from $1,950 2017-02-13
Miineport E1 Firmware HIGH 7.5
CVE-2016-9344

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able t…

Fix: after 1.7
Fix from $1,950 2017-02-13