Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.7 CVE-2024-11165 An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. T… Patch available Fix from $1,6002024-11-13 CRITICAL 9.8 CVE-2024-52009 Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (… Atlantis 0.30.0+ Fix from $2,3002024-11-08 MEDIUM 5.5 CVE-2024-51752 The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affecte… Authkit Nextjs 0.13.2+ Fix from $1,6002024-11-05 MEDIUM 5.5 CVE-2024-51528 Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confi… Emui No fix yet Fix from $1,6002024-11-05 MEDIUM 5.3 CVE-2024-10544 The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 through … Mitigation only Fix from $1,6002024-10-31 MEDIUM 5.5 CVE-2024-44239 An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPadOS 17.7… Ipados 2.1 / 11.1+ Fix from $1,6002024-10-28 MEDIUM 5.5 CVE-2024-49750 The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard op… Snowflake Connector 3.12.3+ Fix from $1,6002024-10-24 MEDIUM 5.5 CVE-2024-44205 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and… Ipados 12.7.6 / 13.6.8+ Fix from $1,6002024-10-24 MEDIUM 6.5 CVE-2023-22649 A vulnerability has been identified which may lead to sensitive data being leaked into Rancher's audit logs. [Rancher Audit Logging](https://rancherm… Rancher 2.6.14 / 2.7.10+ Fix from $1,6002024-10-16 MEDIUM 5.5 CVE-2024-8264 Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed loggi… Robot Schedule 3.05+ Fix from $1,6002024-10-09 MEDIUM 6.5 CVE-2024-9466EPSS 13% A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usern… Expedition 1.2.96+ Fix from $1,6002024-10-09 MEDIUM 5.3 CVE-2024-9621 A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be … Mitigation only Fix from $1,6002024-10-08 MEDIUM 5.3 CVE-2024-47913 An issue was discovered in the AbuseFilter extension for MediaWiki before 1.39.9, 1.40.x and 1.41.x before 1.41.3, and 1.42.x before 1.42.2. An API c… Mediawiki 1.39.9 / 1.41.3+ Fix from $1,6002024-10-04 HIGH 8.6 CVE-2024-20490 A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an a… Nexus Dashboard Fabric Controller 4.2 / 4.4.1.1012+ Fix from $1,9502024-10-02 HIGH 8.6 CVE-2024-20491 A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive … Nexus Dashboard Fabric Controller 4.2 / 4.4.1.1012+ Fix from $1,9502024-10-02 HIGH 7.5 CVE-2024-8609 Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information. This issue affects V… Valeapp 2.0.0+ Fix from $1,9502024-09-27 MEDIUM 6.5 CVE-2022-49037 Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote … Drive Client 3.3.0-15082+ Fix from $1,6002024-09-26 HIGH 7.5 CVE-2024-47083 Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in th… Power Platform Terraform Provider after 3.0.0 Fix from $1,9502024-09-25 MEDIUM 5.5 CVE-2024-7421 An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to… Remote Desktop Manager 2024.3.10+ Fix from $1,6002024-09-25 MEDIUM 5.3 CVE-2024-43990 Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: … No fix yet Fix from $1,6002024-09-25 MEDIUM 5.5 CVE-2024-44166 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS… macOS 13.7 / 14.7+ Fix from $1,6002024-09-17 MEDIUM 5.5 CVE-2024-8775 A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook… Mitigation only Fix from $1,6002024-09-14 MEDIUM 5.5 CVE-2024-4472 An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting f… GitLab 17.1.7 / 17.2.5+ Fix from $1,6002024-09-12 HIGH 7.5 CVE-2022-26322 Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST … Identity Manager Rest Driver 1.1.2.0200+ Fix from $1,9502024-09-12 CRITICAL 9.1 CVE-2021-22533 Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000. Edirectory 9.2.4.0000+ Fix from $2,3002024-09-12 MEDIUM 5.5 CVE-2021-22518 A vulnerability identified in OpenText™ Identity Manager AzureAD Driver that allows logging of sensitive information into log file. This impacts all… Identity Manager Azuread Driver 5.1.4.0+ Fix from $1,6002024-09-12 MEDIUM 5.5 CVE-2024-42344 A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information… Sinema Remote Connect Client 3.2+ Fix from $1,6002024-09-10 MEDIUM 5.5 CVE-2024-43781 A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection wit… Mitigation only Fix from $1,6002024-09-10 HIGH 7.5 CVE-2024-20440EPSS 52% A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerabili… Smart License Utility Mitigation only Fix from $1,9502024-09-04 MEDIUM 6.5 CVE-2024-8365 Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit devic… Vault 1.16.9 / 1.17.5+ Fix from $1,6002024-09-02