Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Control System MEDIUM 6.5
CVE-2026-4901

AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized…

Fix: 9.8.5+
Fix from $1,600 2026-04-09
Elastic Cloud Storage MEDIUM 5.5
CVE-2026-28261

Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of …

Fix: 4.1.0.3 / 4.2.0.1+
Fix from $1,600 2026-04-08
Tivoli Netcool\/impact MEDIUM 5.5
CVE-2026-4788

IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.

Fix: 7.1.0.38+
Fix from $1,600 2026-04-08
Cassandra MEDIUM 5.5
CVE-2026-27315

Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh co…

Fix: 4.0.20+
Fix from $1,600 2026-04-07
Haxiam HIGH 7.5
CVE-2026-35185

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes …

No fix yet
Fix from $1,950 2026-04-06
Filezilla Client MEDIUM 5.5
CVE-2019-25683

FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by…

No fix yet
Fix from $1,600 2026-04-05
Flx MEDIUM 6.5
CVE-2026-4819

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

Fix: 4.1.0+
Fix from $1,600 2026-03-31
Openclaw HIGH 7.5
CVE-2026-32982

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error…

Fix: 2026.3.13+
Fix from $1,950 2026-03-31
Unclassified HIGH 7.3
CVE-2024-11604

Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 …

Mitigation only
Fix from $1,950 2026-03-27
Ipados MEDIUM 5.5
CVE-2026-28868

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Ipados MEDIUM 5.5
CVE-2026-20668

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequ…

Fix: 14.8.5 / 15.7.5+
Fix from $1,600 2026-03-25
Oneuptime MEDIUM 6.5
CVE-2026-32598

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL —…

Fix: 10.0.24+
Fix from $1,600 2026-03-13
Splunk MEDIUM 6.5
CVE-2026-20165

In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.…

Fix: 9.3.10 / 9.3.2411.124+
Fix from $1,600 2026-03-11
Jimeng Web Mcp Server MEDIUM 5.3
CVE-2025-70040

An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an at…

No fix yet
Fix from $1,600 2026-03-09
Backstage\/plugin Scaffolder Backend MEDIUM 6.5
CVE-2026-29184

Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction m…

Fix: 3.1.4+
Fix from $1,600 2026-03-07
Zookeeper HIGH 7.5
CVE-2026-24308

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive inf…

Fix: 3.8.6 / 3.9.5+
Fix from $1,950 2026-03-07
Infosphere Information Server MEDIUM 5.3
CVE-2026-1265

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.

Fix: after 11.7.1.6
Fix from $1,600 2026-03-03
Android HIGH 7.7
CVE-2025-48635

In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could l…

Mitigation only
Fix from $1,950 2026-03-02
Linode Provider HIGH 7.7
CVE-2026-27900

The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object sto…

Fix: 3.9.0+
Fix from $1,950 2026-02-26
Configuration Manager HIGH 7.5
CVE-2025-0976

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Cent…

Fix: 8.6.1-00 / 11.0.4-00+
Fix from $1,950 2026-02-25
Configuration Manager MEDIUM 5.2
CVE-2025-5781

Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Sess…

Fix: 8.6.5-00 / 11.0.5-00+
Fix from $1,600 2026-02-25
Airflow MEDIUM 6.5
CVE-2025-27555

Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which…

Fix: 2.11.1+
Fix from $1,600 2026-02-24
Tanos MEDIUM 5.3
CVE-2026-2605

Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.

Fix: 1.8.4.0249 / 1.8.5.0282+
Fix from $1,600 2026-02-20
Interact MEDIUM 6.5
CVE-2026-2350

Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.

Fix: 3.2.196 / 3.5.102+
Fix from $1,600 2026-02-20
Trends MEDIUM 6.5
CVE-2026-1292

Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.

Fix: 3.10.20 / 3.11.79+
Fix from $1,600 2026-02-20
Unclassified MEDIUM 6.5
CVE-2026-1495

The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and p…

Mitigation only
Fix from $1,600 2026-02-10
Windows 10 1607 MEDIUM 5.5
CVE-2026-21222

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

Fix: 10.0.14393.8868 / 10.0.17763.8389+
Fix from $1,600 2026-02-10
Camera Station Pro HIGH 7.8
CVE-2025-11547

AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.

Fix: 6.13.55835+
Fix from $1,950 2026-02-10
Unity Cli MEDIUM 5.5
CVE-2026-25918

unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs se…

Fix: 1.8.2+
Fix from $1,600 2026-02-09
Placipy HIGH 7.5
CVE-2026-25813

PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly…

Mitigation only
Fix from $1,950 2026-02-09