Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.5 CVE-2022-48319 Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0… Checkmk Mitigation only Fix from $1,6002023-02-20 HIGH 7.5 CVE-2022-43930 IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive information may be included in a log… Db2 Patch available Fix from $1,9502023-02-17 MEDIUM 6.5 CVE-2022-43954 An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a r… Fortiportal Patch available Fix from $1,6002023-02-16 HIGH 7.5 CVE-2023-22362 SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the lo… Hong Kong Sushiro Mitigation only Fix from $1,9502023-02-13 MEDIUM 5.5 CVE-2023-21435 Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address infor… Android Mitigation only Fix from $1,6002023-02-09 MEDIUM 6.5 CVE-2023-25163 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting with v2.6.0-rc1 have an output sanitizatio… Argo Cd Patch available Fix from $1,6002023-02-08 HIGH 7.5 CVE-2023-25164 Tinacms is a Git-backed headless content management system with support for visual editing. Sites being built with @tinacms/cli >= 1.0.0 && < 1.0.9 w… Tinacms\/cli 1.0.9+ Fix from $1,9502023-02-08 HIGH 7.5 CVE-2023-24827 syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems. A password disclosure f… Syft Patch available Fix from $1,9502023-02-07 HIGH 7.5 CVE-2021-36544 Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL. Tpcms No fix yet Fix from $1,9502023-02-03 MEDIUM 5.5 CVE-2023-22573 Dell PowerScale OneFS 9.0.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in cloudpool. A low privileged local … Emc Powerscale Onefs 9.1.0.27 / 9.2.1.20+ Fix from $1,6002023-02-01 HIGH 8.1 CVE-2023-22574 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in platform API of IPMI module. A l… Emc Powerscale Onefs 9.1.0.27 / 9.2.1.20+ Fix from $1,9502023-02-01 HIGH 8.8 CVE-2023-22575 Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user cou… Emc Powerscale Onefs 9.1.0.27 / 9.2.1.20+ Fix from $1,9502023-02-01 HIGH 7.8 CVE-2023-22572 Dell PowerScale OneFS 9.1.0.x-9.4.0.x contain an insertion of sensitive information into log file vulnerability in change password api. A low privile… Emc Powerscale Onefs 9.1.0.27 / 9.2.1.20+ Fix from $1,9502023-02-01 MEDIUM 5.5 CVE-2022-45098 Dell PowerScale OneFS, 9.0.0.x-9.4.0.x, contain a cleartext storage of sensitive information vulnerability in S3 component. An authenticated local at… Emc Powerscale Onefs 9.1.0.25 / 9.2.1.18+ Fix from $1,6002023-02-01 MEDIUM 6.4 CVE-2022-3902 An issue has been discovered in GitLab affecting all versions starting from 9.3 before 15.4.6, all versions starting from 15.5 before 15.5.5, all ver… GitLab 15.4.6 / 15.5.5+ Fix from $1,6002023-01-26 MEDIUM 5.5 CVE-2022-20458 The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" build. StatusBarNotification.ge… Android Mitigation only Fix from $1,6002023-01-26 MEDIUM 6.5 CVE-2023-22733 Shopware is an open source commerce platform based on Symfony Framework and Vue js. In affected versions the log module would write out all kind of s… Shopware 6.4.18.1+ Fix from $1,6002023-01-17 HIGH 7.5 CVE-2022-23506 Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Rosco microservice produces mac… Spinnaker 1.27.3 / 1.28.4+ Fix from $1,9502023-01-03 HIGH 7.5 CVE-2022-4858 Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specifi… M Files Server 22.10.11846.0+ Fix from $1,9502022-12-30 MEDIUM 5.3 CVE-2022-43887 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API keys to log files. If these keys… Cognos Analytics 11.1.7+ Fix from $1,6002022-12-19 MEDIUM 6.5 CVE-2022-4311 An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to … Pcvue after 15.2.2 Fix from $1,6002022-12-12 MEDIUM 6.5 CVE-2022-23469 Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulnerability in Traefik displayin… Traefik 2.9.6+ Fix from $1,6002022-12-08 MEDIUM 5.5 CVE-2022-39897 Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information v… Android Mitigation only Fix from $1,6002022-12-08 HIGH 7.5 CVE-2022-2721 In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in… Octopus Server 2022.2.7965 / 2022.3.9163+ Fix from $1,9502022-11-25 MEDIUM 5.3 CVE-2022-41618 Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress. Media Library Assistant 3.01+ Fix from $1,6002022-11-18 HIGH 7.5 CVE-2022-27895 Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying library known as Build2. This … Foundry Build2 1.785.0+ Fix from $1,9502022-11-15 HIGH 7.5 CVE-2022-27896 Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing that console was generating serv… Foundry Code Workbooks 4.461.0+ Fix from $1,9502022-11-14 MEDIUM 5.5 CVE-2022-35719 IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be read by a local user. Mq Internet Pass Thru Patch available Fix from $1,6002022-11-14 MEDIUM 5.5 CVE-2022-44745 Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107. Cyber Protect Home Office 40107+ Fix from $1,6002022-11-07 HIGH 7.8 CVE-2021-44862 Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which sh… Netskope after 91 Fix from $1,9502022-11-03