Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Unclassified MEDIUM 5.1
CVE-2025-24884

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used fo…

Patch available
Fix from $1,600 2025-01-29
Unclassified CRITICAL 9.4
CVE-2024-48852

Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.…

Mitigation only
Fix from $2,300 2025-01-29
Unclassified MEDIUM 5.5
CVE-2025-0736

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information,…

Mitigation only
Fix from $1,600 2025-01-28
Safari HIGH 7.5
CVE-2025-24169

A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to by…

Fix: 15.3 / 18.3+
Fix from $1,950 2025-01-27
macOS MEDIUM 5.5
CVE-2024-54519

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive lo…

Fix: 14.7.2 / 15.2+
Fix from $1,600 2025-01-27
Unclassified MEDIUM 6.3
CVE-2025-24389

Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to …

Mitigation only
Fix from $1,600 2025-01-27
Cloud Pak System MEDIUM 6.5
CVE-2023-38271

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow…

Mitigation only
Fix from $1,600 2025-01-25
Unclassified HIGH 7.1
CVE-2025-24362

In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables …

Patch available
Fix from $1,950 2025-01-24
Youtrack MEDIUM 5.5
CVE-2025-24457

In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs

Fix: 2024.3.55417+
Fix from $1,600 2025-01-21
Urbancode Deploy MEDIUM 5.5
CVE-2024-45091

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files…

Fix: 7.0.5.25 / 7.1.2.21+
Fix from $1,600 2025-01-21
Unclassified MEDIUM 5.5
CVE-2024-11923

Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One)…

Mitigation only
Fix from $1,600 2025-01-18
Unclassified MEDIUM 6.5
CVE-2024-12226

In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. …

Mitigation only
Fix from $1,600 2025-01-16
TYPO3 MEDIUM 5.3
CVE-2024-55891

TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in c…

Mitigation only
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21319

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21320

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21321

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21323

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21316

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Windows 10 21h2 MEDIUM 5.5
CVE-2025-21317

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.19044.5371 / 10.0.19045.5371+
Fix from $1,600 2025-01-14
Windows 10 1507 MEDIUM 5.5
CVE-2025-21318

Windows Kernel Memory Information Disclosure Vulnerability

Fix: 10.0.10240.20890 / 10.0.14393.7699+
Fix from $1,600 2025-01-14
Db2 MEDIUM 5.5
CVE-2024-40679

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive informat…

Mitigation only
Fix from $1,600 2025-01-08
Iterm2 CRITICAL 9.3
CVE-2025-22275

iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tm…

Fix: 3.5.11+
Fix from $2,300 2025-01-03
Unclassified HIGH 7.8
CVE-2024-12569

Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera …

Mitigation only
Fix from $1,950 2024-12-19
macOS MEDIUM 5.5
CVE-2024-54484

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.

Fix: 15.2+
Fix from $1,600 2024-12-12
Unclassified HIGH 8.5
CVE-2024-42407

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Ope…

Mitigation only
Fix from $1,950 2024-12-12
Hcl Launch MEDIUM 5.5
CVE-2024-42196

HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

Fix: 7.0.5.25 / 7.1.2.21+
Fix from $1,600 2024-12-06
Checkmk MEDIUM 5.5
CVE-2024-47094

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets …

Mitigation only
Fix from $1,600 2024-11-29
Brocade Sannav MEDIUM 5.5
CVE-2022-43937

Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned o…

Fix: 2.2.2a+
Fix from $1,600 2024-11-21
Unclassified HIGH 7.5
CVE-2024-52940

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The att…

Mitigation only
Fix from $1,950 2024-11-18
Unclassified MEDIUM 6.5
CVE-2024-11193

An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. Thi…

Patch available
Fix from $1,600 2024-11-13