Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2022-44624 In JetBrains TeamCity version before 2022.10, Password parameters could be exposed in the build log if they contained special characters Teamcity 2022.10+ Fix from $1,9502022-11-03 MEDIUM 5.5 CVE-2022-3191 Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allo… Ops Center Analyzer 10.9.0-00+ Fix from $1,6002022-11-01 MEDIUM 5.5 CVE-2022-41553 Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component)… Infrastructure Analytics Advisor 10.9.0-00+ Fix from $1,6002022-11-01 MEDIUM 6.5 CVE-2022-3499 An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disc… Nessus 10.4.0+ Fix from $1,6002022-10-31 MEDIUM 5.5 CVE-2022-39874 Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout. Account 13.5.01.3+ Fix from $1,6002022-10-07 MEDIUM 5.3 CVE-2022-23716 A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the RBAC features, in deployment… Elastic Cloud Enterprise 3.1.1+ Fix from $1,6002022-09-28 MEDIUM 5.3 CVE-2022-32217 A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext in Rocket.chat logs. Rocket.chat 4.6.4+ Fix from $1,6002022-09-23 MEDIUM 5.3 CVE-2022-40979 In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perforce executable Teamcity 2022.04.4+ Fix from $1,6002022-09-23 HIGH 7.5 CVE-2022-39821 In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical… 1350 Optical Management System Mitigation only Fix from $1,9502022-09-13 HIGH 7.5 CVE-2022-34369 Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertion of sensitive information in… Emc Powerscale Onefs after 9.4.0.3 Fix from $1,9502022-09-02 MEDIUM 5.5 CVE-2022-28625 A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60.01. A low privileged user co… Oneview 6.60.01+ Fix from $1,6002022-08-31 MEDIUM 5.3 CVE-2022-39046 An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads… Glibc No fix yet Fix from $1,6002022-08-31 MEDIUM 6.5 CVE-2022-23715 A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystor… Elastic Cloud Enterprise 3.4.0+ Fix from $1,6002022-08-25 MEDIUM 5.5 CVE-2022-29550 An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This ma… Cloud Agent No fix yet Fix from $1,6002022-08-18 HIGH 7.5 CVE-2022-38149 HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.E… Consul Template 0.29.2+ Fix from $1,9502022-08-17 MEDIUM 5.5 CVE-2022-20278 In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering. This could lead to local inf… Android Mitigation only Fix from $1,6002022-08-12 MEDIUM 5.3 CVE-2022-38133 In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases Teamcity 2022.04.3+ Fix from $1,6002022-08-10 MEDIUM 5.5 CVE-2022-29071 This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certai… Cloudvision Portal after 2022.1.0 Fix from $1,6002022-08-05 HIGH 7.5 CVE-2022-34570 WAVLINK WN579 X3 M79X3.V5030.191012/M79X3.V5030.191012 contains an information leak which allows attackers to obtain the key information via accessin… Wl Wn579x3 Firmware No fix yet Fix from $1,9502022-07-25 HIGH 7.5 CVE-2022-32556 An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes. Couchbase Server 7.1.1+ Fix from $1,9502022-07-21 MEDIUM 6.5 CVE-2022-36321 In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases Teamcity 2022.04.2+ Fix from $1,6002022-07-20 HIGH 7.5 CVE-2022-23141 ZXMP M721 has an information leak vulnerability. Since the serial port authentication on the ZBOOT interface is not effective although it is enabled,… Zxmp M721 Firmware Mitigation only Fix from $1,9502022-07-15 MEDIUM 5.9 CVE-2022-34826 In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs. Couchbase Server Mitigation only Fix from $1,6002022-07-15 MEDIUM 5.3 CVE-2022-33911 An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Un… Couchbase Server 7.0.4+ Fix from $1,6002022-07-12 MEDIUM 5.5 CVE-2022-27549 HCL Launch may store certain data for recurring activities in a plain text format. Hcl Launch Mitigation only Fix from $1,6002022-07-06 HIGH 7.5 CVE-2022-33737 The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random genera… Openvpn Access Server 2.11.0+ Fix from $1,9502022-07-06 HIGH 7.5 CVE-2022-31098 Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. A vulner… Weave Gitops 0.8.1+ Fix from $1,9502022-06-27 MEDIUM 5.5 CVE-2022-20651 A vulnerability in the logging component of Cisco Adaptive Security Device Manager (ASDM) could allow an authenticated, local attacker to view sensit… Adaptive Security Device Manager 7.17.1+ Fix from $1,6002022-06-22 MEDIUM 5.5 CVE-2022-30148 Windows Desired State Configuration (DSC) Information Disclosure Vulnerability Windows 10 Patch available Fix from $1,6002022-06-15 MEDIUM 6.5 CVE-2022-31047 TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal… TYPO3 7.6.57 / 8.7.47+ Fix from $1,6002022-06-14