Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-75485
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, …
Fix unknown
MEDIUM 6.2
CVE-2026-75057
In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log
Fix unknown
MEDIUM 5.5
CVE-2026-59911
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low pri…
Fix unknown
MEDIUM 5.5
CVE-2026-19483
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The …
Storage Scale
No fix yet
MEDIUM 5.5
CVE-2026-19502
MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain…
No fix yet
MEDIUM 5.5
CVE-2026-18097
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to ob…
Db2
No fix yet
MEDIUM 6.5
CVE-2026-68969
Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint…
Airflow
3.3.1+
MEDIUM 6.5
CVE-2026-18710
A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to applica…
No fix yet
MEDIUM 6.3
CVE-2026-71474
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens…
No fix yet
MEDIUM 6.3
CVE-2026-71845
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear…
No fix yet
MEDIUM 5.9
CVE-2026-20708
Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information d…
No fix yet
MEDIUM 6.5
CVE-2026-65945
Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0
Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Ranger
No fix yet
MEDIUM 5.3
CVE-2026-19363
A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda…
No fix yet
MEDIUM 5.4
CVE-2026-46358
OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted …
No fix yet
MEDIUM 5.4
CVE-2026-21766
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific …
No fix yet
MEDIUM 6.5
CVE-2026-20289
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive informa…
Roomos
No fix yet
MEDIUM 5.3
CVE-2026-65311
The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA)
in affected versions exposes an undocumented endpoint that changes
the server's …
No fix yet
HIGH 7.5
CVE-2026-12947
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that coul…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
MEDIUM 6.6
CVE-2026-44105
The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the lo…
No fix yet
HIGH 7.5
CVE-2026-14528
IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
Websphere Application Server
8.5.5.31 / 9.0.5.29+
MEDIUM 5.7
CVE-2026-64800
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
Goland
2026.2+
MEDIUM 6.5
CVE-2026-65589
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secr…
N8n
1.123.64 / 2.29.8+
MEDIUM 5.0
CVE-2026-62211
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust caller…
Openclaw
2026.6.1+
MEDIUM 6.5
CVE-2026-46514
Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword.php:48-53 returned a plainte…
No fix yet
MEDIUM 5.7
CVE-2026-15737
AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore p…
No fix yet
MEDIUM 5.5
CVE-2026-40633
Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log F…
Powerscale Onefs
9.10.1.8 / 9.13.1.0+
MEDIUM 5.5
CVE-2026-50316
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
Windows 10 21h2
10.0.19044.7548 / 10.0.19045.7548+
CRITICAL 9.2
CVE-2026-22098
Various sensitive information such as passwords and charging card UIDs are written to log files.
Mitigation only
MEDIUM 5.5
CVE-2026-56459
HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure. The application stores potentially sensitive information in log f…
Hcl Devops Deploy
7.3.2.19 / 8.0.1.14+
HIGH 8.1
CVE-2026-54652
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any authenticated user including the…
Patch available