Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Youtrack MEDIUM 6.5
CVE-2026-25846

In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs

Fix: 2025.3.119033+
Fix from $1,600 2026-02-09
Autogpt Platform HIGH 8.1
CVE-2026-22038

AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio…

Fix: 0.6.46+
Fix from $1,950 2026-02-04
Rustfs HIGH 7.5
CVE-2026-24762

RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access ke…

Mitigation only
Fix from $1,950 2026-02-03
Vllm CRITICAL 9.8
CVE-2026-22778

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim…

Fix: 0.14.1+
Fix from $2,300 2026-02-02
Unclassified MEDIUM 5.0
CVE-2026-0936

An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local att…

Mitigation only
Fix from $1,600 2026-01-29
Linkis MEDIUM 6.5
CVE-2025-59355

A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter s…

Fix: 1.8.0+
Fix from $1,600 2026-01-19
macOS MEDIUM 5.5
CVE-2025-43508

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

Mitigation only
Fix from $1,600 2026-01-16
Rustfs HIGH 7.5
CVE-2026-22782

RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log …

Patch available
Fix from $1,950 2026-01-16
Airflow HIGH 7.5
CVE-2025-68675

In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authe…

Fix: 3.1.6+
Fix from $1,950 2026-01-16
Windows Server 2016 MEDIUM 6.2
CVE-2026-20818

Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally.

Fix: 10.0.14393.8783 / 10.0.17763.8276+
Fix from $1,600 2026-01-13
Hermes MEDIUM 5.0
CVE-2026-22798

hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcomma…

Fix: 0.9.1+
Fix from $1,600 2026-01-12
Unclassified MEDIUM 5.6
CVE-2025-68919

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is…

Mitigation only
Fix from $1,600 2025-12-24
Turms MEDIUM 6.0
CVE-2025-66910

Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdm…

No fix yet
Fix from $1,600 2025-12-19
Unclassified HIGH 7.5
CVE-2025-14437

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the…

Mitigation only
Fix from $1,950 2025-12-18
Ipados MEDIUM 5.5
CVE-2025-43475

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensit…

Fix: 26.2+
Fix from $1,600 2025-12-17
Docker Desktop HIGH 7.5
CVE-2025-13743

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaki…

Fix: 4.54.0+
Fix from $1,950 2025-12-09
Fortiproxy MEDIUM 6.6
CVE-2024-47570

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; Fo…

Fix: 7.2.8 / 7.2.12+
Fix from $1,600 2025-12-09
Storage Defender Resiliency Service MEDIUM 6.5
CVE-2025-64650

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.

Fix: after 2.0.18
Fix from $1,600 2025-12-08
Unclassified HIGH 8.7
CVE-2020-36876

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated …

No fix yet
Fix from $1,950 2025-12-05
Community.general MEDIUM 5.5
CVE-2025-14010

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica…

Patch available
Fix from $1,600 2025-12-04
Coder MEDIUM 5.5
CVE-2025-66411

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests…

Fix: 2.26.5 / 2.27.7+
Fix from $1,600 2025-12-03
GitLab MEDIUM 5.3
CVE-2025-13611

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authe…

Fix: 18.4.5 / 18.5.3+
Fix from $1,600 2025-11-26
Sy Gpon 1110 Wdont Firmware CRITICAL 9.0
CVE-2025-63729

An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SS…

No fix yet
Fix from $2,300 2025-11-25
Upkeeper Manager MEDIUM 6.5
CVE-2025-11446

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This iss…

Fix: 5.2.13.1+
Fix from $1,600 2025-11-19
Fortiadc MEDIUM 6.5
CVE-2025-54971

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all v…

Fix: 7.4.3+
Fix from $1,600 2025-11-18
Windows 10 1507 MEDIUM 5.5
CVE-2025-62209

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-11-11
Windows 10 1507 MEDIUM 5.5
CVE-2025-62208

Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-11-11
Wax610y Firmware MEDIUM 5.5
CVE-2025-12940

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig I…

Fix: 11.8.0.10+
Fix from $1,600 2025-11-11
Unclassified CRITICAL 9.8
CVE-2025-11008

The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. Thi…

Mitigation only
Fix from $2,300 2025-11-04
Ipados MEDIUM 5.5
CVE-2025-43426

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to …

Fix: 26.1+
Fix from $1,600 2025-11-04