Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.8 CVE-2021-36289 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit t… Emc Unity Operating Environment after 8.1.21.266 Fix from $1,9502022-01-25 MEDIUM 5.5 CVE-2022-22703 In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe install… Network Security 2.1.1 / 3.0.2+ Fix from $1,6002022-01-17 MEDIUM 5.5 CVE-2021-44234 SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expos… Business One Mitigation only Fix from $1,6002022-01-14 MEDIUM 5.5 CVE-2021-39032 IBM Sterling Gentran:Server for Microsoft Windows 5.3 stores potentially sensitive information in log files that could be read by a local user. IBM X… Sterling Gentran Patch available Fix from $1,6002022-01-14 MEDIUM 5.5 CVE-2021-45449 Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. Th… Docker Desktop Mitigation only Fix from $1,6002022-01-12 HIGH 7.5 CVE-2021-45034 A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER MODULE WITH I/O -40/+70°C (Al… Cp 8000 Master Module With I\/o 25\/\+70 Firmware 16.20+ Fix from $1,9502022-01-11 HIGH 7.5 CVE-2021-34797 Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with … Geode after 1.13.4 Fix from $1,9502022-01-04 MEDIUM 6.7 CVE-2021-36318 Dell EMC Avamar versions 18.2,19.1,19.2,19.3,19.4 contain a plain-text password storage vulnerability. A high privileged user could potentially explo… Emc Avamar Server Patch available Fix from $1,6002021-12-21 MEDIUM 5.5 CVE-2021-0997 In handleUpdateNetworkState of GnssNetworkConnectivityHandler.java , there is a possible APN disclosure due to log information disclosure. This could… Android Patch available Fix from $1,6002021-12-15 HIGH 7.5 CVE-2021-37861 Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails. Mattermost after 6.0.2 Fix from $1,9502021-12-09 HIGH 7.5 CVE-2021-34800 Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147 Agent Patch available Fix from $1,9502021-11-29 MEDIUM 5.5 CVE-2021-21561 Dell PowerScale OneFS version 8.1.2 contains a sensitive information exposure vulnerability. This would allow a malicious user with ISI_PRIV_LOGIN_SS… Emc Powerscale Onefs Patch available Fix from $1,6002021-11-23 MEDIUM 5.5 CVE-2021-37036 There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and V100R005C10. Due to the improperly storage of specif… Ecns280 Td Firmware Mitigation only Fix from $1,6002021-11-23 MEDIUM 5.5 CVE-2021-36340 Dell EMC SCG 5.00.00.10 and earlier, contain a sensitive information disclosure vulnerability. A local malicious user may exploit this vulnerability … Secure Connect Gateway Mitigation only Fix from $1,6002021-11-20 MEDIUM 6.5 CVE-2021-22030 In versions of Greenplum database prior to 5.28.14 and 6.17.0, certain statements execution led to the storage of sensitive(credential) information i… Greenplum 5.28.14 / 6.17.0+ Fix from $1,6002021-11-19 MEDIUM 6.5 CVE-2021-3791 An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on… Halo\+ Camera Firmware 03.40.00 / 03.40.02+ Fix from $1,6002021-11-12 MEDIUM 5.5 CVE-2021-40364 A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All … Simatic Pcs 7 9.1+ Fix from $1,6002021-11-09 MEDIUM 5.5 CVE-2020-10052 A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as … Simatic Rtls Locating Manager 2.12+ Fix from $1,6002021-11-09 MEDIUM 6.7 CVE-2021-39913 Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versions starting from 14.3 before… GitLab 14.2.6 / 14.3.4+ Fix from $1,6002021-11-05 HIGH 7.5 CVE-2021-20129 An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs. Vigorconnect No fix yet Fix from $1,9502021-10-13 MEDIUM 6.1 CVE-2021-39246 Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses. Exact… Tor Browser after 10.5.6 Fix from $1,6002021-09-24 CRITICAL 9.9 CVE-2021-32724 check-spelling is a github action which provides CI spell checking. In affected versions and for a repository with the [check-spelling action](https:… Check Spelling 0.0.19+ Fix from $2,3002021-09-09 MEDIUM 5.5 CVE-2021-32801 Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially s… Nextcloud Server 20.0.12 / 21.0.4+ Fix from $1,6002021-09-07 MEDIUM 6.1 CVE-2021-22929 An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connect… Brave 1.28.62+ Fix from $1,6002021-08-31 HIGH 7.5 CVE-2021-22024 The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with net… Cloud Foundation 8.5.0+ Fix from $1,9502021-08-30 HIGH 8.8 CVE-2021-39291 Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are … Netmodule Router Software 4.3.0.113 / 4.4.0.111+ Fix from $1,9502021-08-23 MEDIUM 6.5 CVE-2021-37709 Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure direct object reference of log… Shopware 6.4.3.1+ Fix from $1,6002021-08-16 MEDIUM 5.5 CVE-2021-36278 Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files. A local malicious… Emc Powerscale Onefs after 9.1.0 Fix from $1,6002021-08-16 HIGH 7.8 CVE-2021-21601 Dell EMC Data Protection Search, 19.4 and prior, and IDPA, 2.6.1 and prior, contain an Information Exposure in Log File Vulnerability in CIS. A local… Emc Data Protection Search 2.7 / 19.5+ Fix from $1,9502021-08-10 CRITICAL 9.8 CVE-2021-37759 A Session ID leak in the DEBUG log file in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID… Graylog 4.1.2+ Fix from $2,3002021-07-31