Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Cf Deployment HIGH 7.5
CVE-2025-22246

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.

Fix: 49.0.0 / 77.32.0+
Fix from $1,950 2025-05-13
Ipados HIGH 7.6
CVE-2025-31213

A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Vent…

Fix: 13.7.6 / 14.7.6+
Fix from $1,950 2025-05-12
Unclassified MEDIUM 5.2
CVE-2025-3911

Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of s…

Mitigation only
Fix from $1,600 2025-04-29
Firefox MEDIUM 5.3
CVE-2025-4090

A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed…

Fix: 138.0+
Fix from $1,600 2025-04-29
Teamcity MEDIUM 6.5
CVE-2025-46432

In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs

Fix: 2025.03.1+
Fix from $1,600 2025-04-25
Checkmk HIGH 7.5
CVE-2025-2092

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site auth…

Fix: 2.1.0+
Fix from $1,950 2025-04-22
Unclassified MEDIUM 5.5
CVE-2025-2300

Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Cente…

Mitigation only
Fix from $1,600 2025-04-22
Unclassified MEDIUM 5.9
CVE-2025-24651

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embe…

Mitigation only
Fix from $1,600 2025-04-17
Artemis MEDIUM 6.5
CVE-2025-27391

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th…

Fix: 2.40.0+
Fix from $1,600 2025-04-09
Pulsar MEDIUM 6.5
CVE-2025-30677

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka …

Fix: 3.0.11 / 3.3.6+
Fix from $1,600 2025-04-09
Unclassified MEDIUM 6.5
CVE-2025-25013

Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automat…

Mitigation only
Fix from $1,600 2025-04-08
Azure Local Cluster MEDIUM 5.7
CVE-2025-25002

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent networ…

Fix: 2411.2+
Fix from $1,600 2025-04-08
Unclassified HIGH 8.2
CVE-2025-31479

canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to …

Patch available
Fix from $1,950 2025-04-02
Unclassified MEDIUM 5.3
CVE-2025-31788

Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all…

Mitigation only
Fix from $1,600 2025-04-01
Infosphere Information Server HIGH 7.5
CVE-2024-7577

IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product.

Fix: 11.7.1+
Fix from $1,950 2025-03-29
Devops Deploy MEDIUM 5.5
CVE-2025-1998

IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.…

Fix: 7.1.2.22 / 7.2.3.15+
Fix from $1,600 2025-03-27
Teamcity MEDIUM 6.5
CVE-2025-31139

In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log

Fix: 2025.03+
Fix from $1,600 2025-03-27
Hcl Devops Deploy MEDIUM 5.5
CVE-2025-0273

HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user.

Fix: 7.1.2.22 / 7.2.3.15+
Fix from $1,600 2025-03-27
Splunk MEDIUM 5.7
CVE-2025-20231

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk C…

Fix: 3.7.23 / 3.8.38+
Fix from $1,600 2025-03-26
Unclassified HIGH 7.6
CVE-2025-30205

kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function…

Patch available
Fix from $1,950 2025-03-24
Fortimanager MEDIUM 6.5
CVE-2024-40585

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 a…

Fix: 6.2.12 / 6.4.13+
Fix from $1,600 2025-03-14
Unclassified MEDIUM 6.0
CVE-2025-2002

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FT…

Mitigation only
Fix from $1,600 2025-03-12
Nomad MEDIUM 6.5
CVE-2025-1296

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in aud…

Fix: 1.7.19 / 1.8.11+
Fix from $1,600 2025-03-10
Unclassified MEDIUM 5.2
CVE-2025-1696

A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via applica…

Mitigation only
Fix from $1,600 2025-03-06
Unclassified MEDIUM 6.4
CVE-2025-1979

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged…

Patch available
Fix from $1,600 2025-03-06
Pie Register HIGH 7.5
CVE-2024-13818

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for…

Fix: after 3.8.3.9
Fix from $1,950 2025-02-21
Checkmk HIGH 7.5
CVE-2025-1075

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials …

Fix: 2.1.0+
Fix from $1,950 2025-02-19
Unclassified MEDIUM 5.1
CVE-2022-35202

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private k…

Mitigation only
Fix from $1,600 2025-02-11
Harmonyos HIGH 7.5
CVE-2024-57957

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service…

Mitigation only
Fix from $1,950 2025-02-06
Unclassified HIGH 7.5
CVE-2025-24556

Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue aff…

Mitigation only
Fix from $1,950 2025-02-03