Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2021-36289
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit t…
Emc Unity Operating Environment
after 8.1.21.266
MEDIUM 5.5
CVE-2022-22703
In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe install…
Network Security
2.1.1 / 3.0.2+
MEDIUM 5.5
CVE-2021-44234
SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos…
Business One
Mitigation only
MEDIUM 5.5
CVE-2021-39032
IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X…
Sterling Gentran
Patch available
MEDIUM 5.5
CVE-2021-45449
Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. Th…
Docker Desktop
Mitigation only
HIGH 7.5
CVE-2021-45034
A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al…
Cp 8000 Master Module With I\/o 25\/\+70 Firmware
16.20+
HIGH 7.5
CVE-2021-34797
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with …
Geode
after 1.13.4
MEDIUM 6.7
CVE-2021-36318
Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially explo…
Emc Avamar Server
Patch available
MEDIUM 5.5
CVE-2021-0997
In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could…
Android
Patch available
HIGH 7.5
CVE-2021-37861
Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
Mattermost
after 6.0.2
HIGH 7.5
CVE-2021-34800
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147
Agent
Patch available
MEDIUM 5.5
CVE-2021-21561
Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SS…
Emc Powerscale Onefs
Patch available
MEDIUM 5.5
CVE-2021-37036
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specif…
Ecns280 Td Firmware
Mitigation only
MEDIUM 5.5
CVE-2021-36340
Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability …
Secure Connect Gateway
Mitigation only
MEDIUM 6.5
CVE-2021-22030
In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information i…
Greenplum
5.28.14 / 6.17.0+
MEDIUM 6.5
CVE-2021-3791
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on…
Halo\+ Camera Firmware
03.40.00 / 03.40.02+
MEDIUM 5.5
CVE-2021-40364
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All …
Simatic Pcs 7
9.1+
MEDIUM 5.5
CVE-2020-10052
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as …
Simatic Rtls Locating Manager
2.12+
MEDIUM 6.7
CVE-2021-39913
Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before…
GitLab
14.2.6 / 14.3.4+
HIGH 7.5
CVE-2021-20129
An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.
Vigorconnect
No fix yet
MEDIUM 6.1
CVE-2021-39246
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact…
Tor Browser
after 10.5.6
CRITICAL 9.9
CVE-2021-32724
check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https:…
Check Spelling
0.0.19+
MEDIUM 5.5
CVE-2021-32801
Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially s…
Nextcloud Server
20.0.12 / 21.0.4+
MEDIUM 6.1
CVE-2021-22929
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connect…
Brave
1.28.62+
HIGH 7.5
CVE-2021-22024
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with net…
Cloud Foundation
8.5.0+
HIGH 8.8
CVE-2021-39291
Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are …
Netmodule Router Software
4.3.0.113 / 4.4.0.111+
MEDIUM 6.5
CVE-2021-37709
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log…
Shopware
6.4.3.1+
MEDIUM 5.5
CVE-2021-36278
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious…
Emc Powerscale Onefs
after 9.1.0
HIGH 7.8
CVE-2021-21601
Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local…
Emc Data Protection Search
2.7 / 19.5+
CRITICAL 9.8
CVE-2021-37759
A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID…
Graylog
4.1.2+