Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.8 CVE-2024-27157 The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypa… No fix yet Fix from $1,6002024-06-14 MEDIUM 6.8 CVE-2024-27156 The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can … Mitigation only Fix from $1,6002024-06-14 MEDIUM 6.2 CVE-2024-27154 Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL. Mitigation only Fix from $1,6002024-06-14 HIGH 7.5 CVE-2024-5908 A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, i… Globalprotect 5.1.12 / 6.0.8+ Fix from $1,9502024-06-12 MEDIUM 5.3 CVE-2024-32811 Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affects USPS Shippin… Mitigation only Fix from $1,6002024-06-09 HIGH 7.5 CVE-2024-25095 Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: … Easy Forms For Mailchimp after 6.9.0 Fix from $1,9502024-06-04 HIGH 7.5 CVE-2024-36127 apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability… Patch available Fix from $1,9502024-06-03 MEDIUM 5.3 CVE-2024-34798 Insertion of Sensitive Information into Log File vulnerability in Lukman Nakib Debug Log – Manger Tool.This issue affects Debug Log – Manger Tool: fr… No fix yet Fix from $1,6002024-06-03 MEDIUM 5.1 CVE-2024-31216 The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3… Patch available Fix from $1,6002024-05-15 MEDIUM 6.5 CVE-2024-3744 A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These to… Mitigation only Fix from $1,6002024-05-15 CRITICAL 9.8 CVE-2024-34706 Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is expose… Patch available Fix from $2,3002024-05-14 HIGH 7.5 CVE-2024-34559 Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from n/a through 1.4.0. Mitigation only Fix from $1,9502024-05-14 MEDIUM 5.3 CVE-2024-34550 Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynamics 365 Integration: from… Mitigation only Fix from $1,6002024-05-14 MEDIUM 5.5 CVE-2024-34353 The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption state machine in Rust. In Ma… Patch available Fix from $1,6002024-05-14 MEDIUM 5.5 CVE-2023-40694 IBM Watson CP4D Data Stores 4.0.0 through 4.8.4 stores potentially sensitive information in log files that could be read by a local user. IBM X-Forc… Watson Cp4d Data Stores 4.8.5+ Fix from $1,6002024-05-07 HIGH 7.5 CVE-2024-34527 spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged. Mitigation only Fix from $1,9502024-05-06 MEDIUM 5.3 CVE-2024-33922 Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Media Cleaner: from n/a through 6… Mitigation only Fix from $1,6002024-05-02 MEDIUM 5.5 CVE-2024-2877 Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby… Vault 1.15.8+ Fix from $1,6002024-04-30 HIGH 7.5 CVE-2024-33637 Insertion of Sensitive Information into Log File vulnerability in Solid Plugins Solid Affiliate.This issue affects Solid Affiliate: from n/a through … Mitigation only Fix from $1,9502024-04-29 HIGH 7.5 CVE-2024-32953 Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5. Mitigation only Fix from $1,9502024-04-24 MEDIUM 5.3 CVE-2024-32788 Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG Joomla to WordPress.This issue affects FG Joomla to WordPress: f… No fix yet Fix from $1,6002024-04-24 MEDIUM 6.5 CVE-2024-32051 Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is exploited, a network-adjacent… Mitigation only Fix from $1,6002024-04-24 MEDIUM 5.5 CVE-2023-22869 IBM Aspera Faspex 5.0.0 through 5.0.7 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 244… Aspera Faspex 5.0.8+ Fix from $1,6002024-04-19 HIGH 8.6 CVE-2024-29959 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's … Brocade Sannav 2.3.0a+ Fix from $1,9502024-04-19 HIGH 7.5 CVE-2024-29957 When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. Thi… Brocade Sannav 2.3.0a+ Fix from $1,9502024-04-19 MEDIUM 6.5 CVE-2024-29958 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to re… Brocade Sannav 2.3.0a+ Fix from $1,6002024-04-19 MEDIUM 5.3 CVE-2024-32686 Insertion of Sensitive Information into Log File vulnerability in Inisev Backup Migration.This issue affects Backup Migration: from n/a through 1.4.3. No fix yet Fix from $1,6002024-04-18 MEDIUM 5.5 CVE-2024-29955 A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup log… Brocade Sannav 2.3.0a+ Fix from $1,6002024-04-17 MEDIUM 5.3 CVE-2024-32513 Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO fo… Mitigation only Fix from $1,6002024-04-17 MEDIUM 6.8 CVE-2024-22440 A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability could cause disclosure of sensi… No fix yet Fix from $1,6002024-04-17