Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Apisix HIGH 7.5
CVE-2025-62232

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…

Fix: 3.14.0+
Fix from $1,950 2025-10-31
Go MEDIUM 5.3
CVE-2025-58189

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is…

Fix: 1.24.8 / 1.25.2+
Fix from $1,600 2025-10-29
Unclassified HIGH 7.5
CVE-2025-11504

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-co…

Mitigation only
Fix from $1,950 2025-10-24
Openbao HIGH 7.5
CVE-2025-62513

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein …

Fix: 2.4.2+
Fix from $1,950 2025-10-22
Unclassified MEDIUM 5.3
CVE-2025-10486

The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly …

Mitigation only
Fix from $1,600 2025-10-15
Windows Server 2012 MEDIUM 6.2
CVE-2025-59258

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information loca…

Fix: 10.0.17763.7919 / 10.0.20348.4294+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59203

Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-59197

Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.

Fix: 10.0.10240.21161 / 10.0.14393.8519+
Fix from $1,600 2025-10-14
Windows Server 2022 23h2 MEDIUM 5.5
CVE-2025-47979

Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.

Fix: 10.0.25398.1913+
Fix from $1,600 2025-10-14
Elasticsearch MEDIUM 5.7
CVE-2025-37727

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing reques…

Fix: 8.18.8 / 8.19.5+
Fix from $1,600 2025-10-10
Unclassified MEDIUM 5.3
CVE-2025-10645

The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::lo…

Mitigation only
Fix from $1,600 2025-10-07
Watsonx.data MEDIUM 5.5
CVE-2025-36144

IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

Mitigation only
Fix from $1,600 2025-09-27
Unclassified MEDIUM 5.3
CVE-2025-9985EPSS 11%

The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 t…

Mitigation only
Fix from $1,600 2025-09-26
Virtual Appliance Application HIGH 7.8
CVE-2025-34188

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployme…

Fix: 1.0.735 / 20.0.1330+
Fix from $1,950 2025-09-19
Eve X1 Server Firmware HIGH 7.5
CVE-2025-34183

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attacke…

Fix: after 4.7.18.0
Fix from $1,950 2025-09-16
Ipados MEDIUM 5.5
CVE-2025-43354

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchO…

Fix: 26.0+
Fix from $1,600 2025-09-15
Ipados MEDIUM 5.5
CVE-2025-43303

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchO…

Fix: 26.0+
Fix from $1,600 2025-09-15
Hoverfly HIGH 7.5
CVE-2025-54376

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by…

Fix: 1.12.0+
Fix from $1,950 2025-09-10
Powerprotect Data Manager HIGH 7.8
CVE-2025-43888

Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A …

Fix: 19.21+
Fix from $1,950 2025-09-10
Axxon One MEDIUM 5.5
CVE-2025-10221

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier…

Fix: after 2.0.4
Fix from $1,600 2025-09-10
Unclassified MEDIUM 6.5
CVE-2025-7445

Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.

Mitigation only
Fix from $1,600 2025-09-05
Unclassified MEDIUM 5.5
CVE-2025-23261

NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially dis…

Mitigation only
Fix from $1,600 2025-09-04
Upkeeper Manager MEDIUM 6.5
CVE-2025-8663

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This iss…

Fix: after 5.2.12
Fix from $1,600 2025-09-03
Unclassified HIGH 7.4
CVE-2025-41690

A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s even…

Mitigation only
Fix from $1,950 2025-09-02
App Connect Enterprise Certified Containers Operands MEDIUM 5.5
CVE-2025-36133

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potential…

Fix: 12.15.0+
Fix from $1,600 2025-09-01
Unclassified MEDIUM 5.9
CVE-2025-57813

traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, su…

Patch available
Fix from $1,600 2025-08-26
Unclassified CRITICAL 9.3
CVE-2025-7426

Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated…

Mitigation only
Fix from $2,300 2025-08-25
Openmanage Enterprise MEDIUM 6.5
CVE-2025-38745

Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backu…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 6.8
CVE-2025-8864

Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs

Mitigation only
Fix from $1,600 2025-08-11
Control M\/server HIGH 7.8
CVE-2025-48709

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …

Mitigation only
Fix from $1,950 2025-08-07