Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.5 CVE-2023-41253 When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Sof… Big Ip Domain Name System 15.1.9 / 16.1.4+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-43485 When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software version… Big Iq Centralized Management 8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-5182 Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has… Subiquity after 23.09.1 Fix from $1,6002023-10-07 MEDIUM 5.5 CVE-2023-45241 Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before b… Agent Mitigation only Fix from $1,6002023-10-05 MEDIUM 6.3 CVE-2023-4380 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T… Ansible Automation Platform Mitigation only Fix from $1,6002023-10-04 HIGH 7.5 CVE-2023-43261EPSS 59% An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. Ur5x Firmware 35.3.0.7+ Fix from $1,9502023-10-04 HIGH 7.5 CVE-2023-3349 Information exposure vulnerability in IBERMATICA RPS 2019, which exploitation could allow an unauthenticated user to retrieve sensitive information, … Ibermatica Rps Mitigation only Fix from $1,9502023-10-03 HIGH 7.5 CVE-2023-3350 A Cryptographic Issue vulnerability has been found on IBERMATICA RPS, affecting version 2019. By firstly downloading the log file, an attacker could … Ibermatica Rps Mitigation only Fix from $1,9502023-10-03 MEDIUM 5.5 CVE-2023-3335 Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator on Linux allows local users  to gain sensitive inf… Ops Center Administrator 10.9.3-00+ Fix from $1,6002023-10-03 HIGH 7.5 CVE-2023-44155 Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. Cyber Protect 15+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-41308 Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality. Emui Mitigation only Fix from $1,9502023-09-27 CRITICAL 9.6 CVE-2023-40029 Argo CD is a declarative continuous deployment for Kubernetes. Argo CD Cluster secrets might be managed declaratively using Argo CD / kubectl apply. … Argo Cd 2.6.15 / 2.7.14+ Fix from $2,3002023-09-07 MEDIUM 5.3 CVE-2023-41934 Jenkins Pipeline Maven Integration Plugin 1330.v18e473854496 and earlier does not properly mask (i.e., replace with asterisks) usernames of credentia… Pipeline Maven Integration after 1330.v18e473854496 Fix from $1,6002023-09-06 MEDIUM 5.5 CVE-2023-4688 Sensitive information leak through log files. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 35433. Agent Mitigation only Fix from $1,6002023-08-31 HIGH 7.5 CVE-2021-32050 Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The pu… C\+\+ 1.1.1 / 1.9.2+ Fix from $1,9502023-08-29 MEDIUM 5.3 CVE-2023-39348 Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's… Spinnaker 1.28.8 / 1.29.6+ Fix from $1,6002023-08-28 MEDIUM 6.5 CVE-2023-32491 Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could pote… Powerscale Onefs after 9.5.0.3 Fix from $1,6002023-08-16 MEDIUM 6.5 CVE-2020-24804 Plaintext Password vulnerability in AddAdmin.py in cms-dev/cms v1.4.rc1, allows attackers to gain sensitive information via audit logs. Cms Mitigation only Fix from $1,6002023-08-11 HIGH 7.5 CVE-2023-4108 Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged Mattermost 7.8.8 / 7.9.6+ Fix from $1,9502023-08-11 HIGH 7.5 CVE-2023-3993 An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all… GitLab 16.0.8 / 16.1.3+ Fix from $1,9502023-08-02 MEDIUM 6.5 CVE-2023-31426 The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers pas… Fabric Operating System 8.2.3d / 9.1.1c+ Fix from $1,6002023-08-01 MEDIUM 6.5 CVE-2023-20891 The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials … Isolation Segment 2.11.35 / 2.11.42+ Fix from $1,6002023-07-26 MEDIUM 5.5 CVE-2023-32447 Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to th… Wyse Thinos 9.4.2103+ Fix from $1,6002023-07-20 MEDIUM 5.5 CVE-2023-32455 Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with l… Wyse Thinos after 9.3.2102 Fix from $1,6002023-07-20 MEDIUM 5.5 CVE-2023-32446 Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with l… Wyse Thinos Mitigation only Fix from $1,6002023-07-20 HIGH 7.5 CVE-2023-26023 Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil… Cloud Pak For Data Patch available Fix from $1,9502023-07-19 HIGH 7.5 CVE-2023-26026 Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerabil… Cloud Pak For Data Patch available Fix from $1,9502023-07-19 MEDIUM 5.5 CVE-2023-37224 An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the l… Archer 6.13.0.1+ Fix from $1,6002023-07-14 MEDIUM 6.5 CVE-2023-20207 A vulnerability in the logging component of Cisco Duo Authentication Proxy could allow an authenticated, remote attacker to view sensitive informatio… Authentication Proxy Mitigation only Fix from $1,6002023-07-12 MEDIUM 6.5 CVE-2023-38064 In JetBrains TeamCity before 2023.05.1 build chain parameters of the "password" type could be written to the agent log Teamcity 2023.05.1+ Fix from $1,6002023-07-12