Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Unclassified MEDIUM 5.5
CVE-2025-23289

NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause sensitive information to be w…

Mitigation only
Fix from $1,600 2025-07-31
Techadvisor MEDIUM 5.5
CVE-2025-26332

TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low pri…

Fix: 3.4 / 6.4.3+
Fix from $1,600 2025-07-30
Techadvisor MEDIUM 5.5
CVE-2025-30105

Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local…

Fix: 3.4 / 6.4.3+
Fix from $1,600 2025-07-30
Ipados MEDIUM 5.5
CVE-2025-43225

A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Vent…

Fix: 13.7.7 / 14.7.7+
Fix from $1,600 2025-07-30
Unclassified MEDIUM 5.1
CVE-2025-53649

"SwitchBot" App for iOS/Android contains an insertion of sensitive information into log file vulnerability in versions V6.24 through V9.12. If this v…

Mitigation only
Fix from $1,600 2025-07-29
Unclassified CRITICAL 9.3
CVE-2025-54120

PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9, the login credentials used d…

Patch available
Fix from $2,300 2025-07-23
Unclassified MEDIUM 6.8
CVE-2025-7371

Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacke…

Mitigation only
Fix from $1,600 2025-07-22
Unclassified MEDIUM 6.3
CVE-2025-54319

An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized access to sensitive information vi…

Mitigation only
Fix from $1,600 2025-07-20
Brocade Active Support Connectivity Gateway CRITICAL 9.1
CVE-2025-6391

Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens wi…

Fix: after 3.2.0
Fix from $2,300 2025-07-17
Adguard For Safari MEDIUM 5.5
CVE-2025-51497

An issue was discovered in AdGuard plugin before 1.11.22 for Safari on MacOS. AdGaurd verbosely logged each url that Safari accessed when the plugin …

Fix: 1.11.22+
Fix from $1,600 2025-07-17
Unclassified MEDIUM 6.9
CVE-2025-54064

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policie…

Mitigation only
Fix from $1,600 2025-07-17
Elastic Cloud Storage MEDIUM 5.5
CVE-2025-30483

Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0 contains an Insertion of Sensitive Information into Log File vulnerability. A low pri…

Fix: 3.8.1.5 / 4.0.0.1+
Fix from $1,600 2025-07-15
Powerflex Manager MEDIUM 6.5
CVE-2025-36599

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged at…

Fix: 4.6.2.1+
Fix from $1,600 2025-07-09
Connect Secure MEDIUM 5.5
CVE-2025-5464

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain t…

Fix: 22.7+
Fix from $1,600 2025-07-08
Connect Secure MEDIUM 5.5
CVE-2025-5463

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 …

Fix: 22.7+
Fix from $1,600 2025-07-08
Jenkins MEDIUM 6.5
CVE-2024-9453

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those l…

Mitigation only
Fix from $1,600 2025-07-04
Unclassified MEDIUM 5.2
CVE-2025-6587

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure…

Mitigation only
Fix from $1,600 2025-07-03
Snyk Cli HIGH 7.2
CVE-2025-6624

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Co…

Fix: 1.1297.3+
Fix from $1,950 2025-06-26
GitLab HIGH 7.5
CVE-2024-7586

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from…

Fix: 17.0.6 / 17.1.4+
Fix from $1,950 2025-06-20
Qradar Security Information And Event Manager MEDIUM 6.2
CVE-2025-36050

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user.

Mitigation only
Fix from $1,600 2025-06-19
Rabbitmq Server MEDIUM 5.5
CVE-2025-50200

RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64.…

Fix: 4.0.8+
Fix from $1,600 2025-06-19
Unclassified MEDIUM 5.1
CVE-2025-2327

A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.

Mitigation only
Fix from $1,600 2025-06-16
Pro Smart Dock Sd25 Firmware MEDIUM 5.5
CVE-2025-36573

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vulnerability. A user with local…

Fix: 01.00.08.01+
Fix from $1,600 2025-06-12
Yii2 Redis MEDIUM 6.5
CVE-2025-48493

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands …

Fix: 2.0.20+
Fix from $1,600 2025-06-05
Unclassified MEDIUM 6.2
CVE-2025-49009

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `Face…

Patch available
Fix from $1,600 2025-06-05
Unclassified MEDIUM 6.2
CVE-2025-48955

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes …

Patch available
Fix from $1,600 2025-06-02
Ipados MEDIUM 5.5
CVE-2025-31199

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.8.2,…

Fix: 2.4 / 15.4+
Fix from $1,600 2025-05-29
Unclassified MEDIUM 5.5
CVE-2025-48374

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding t…

Patch available
Fix from $1,600 2025-05-22
Iotdb HIGH 7.5
CVE-2025-26864

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of…

Fix: 1.3.4+
Fix from $1,950 2025-05-14
Iotdb HIGH 7.5
CVE-2025-26795

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive…

Fix: 1.3.4 / 2.0.2+
Fix from $1,950 2025-05-14