Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
CRITICAL 9.8 CVE-2021-37760 A Session ID leak in the audit log in Graylog before 4.1.2 allows attackers to escalate privileges (to the access level of the leaked session ID). Graylog 4.1.2+ Fix from $2,3002021-07-31 MEDIUM 5.5 CVE-2021-21546 Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vulnerability. A local low-privil… Emc Networker 19.3.0.4+ Fix from $1,6002021-07-29 HIGH 7.5 CVE-2021-28131 Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala lo… Impala 4.0.0+ Fix from $1,9502021-07-22 HIGH 7.5 CVE-2020-21933 An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log … Cx2 Firmware No fix yet Fix from $1,9502021-07-21 HIGH 7.5 CVE-2020-23284 Information disclosure in aspx pages in MV's IDCE application v1.0 allows an attacker to copy and paste aspx pages in the end of the URL application … Idce Mitigation only Fix from $1,9502021-07-20 MEDIUM 6.5 CVE-2021-32767 TYPO3 is an open source PHP based web content management system. In versions 9.0.0 through 9.5.27, 10.0.0 through 10.4.17, and 11.0.0 through 11.3.0,… TYPO3 after 11.3.0 Fix from $1,6002021-07-20 MEDIUM 5.5 CVE-2021-34689 iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A locally authenticated attacker can read the system's Personal Key in world-… Remotepc 7.6.48+ Fix from $1,6002021-07-15 MEDIUM 6.5 CVE-2020-24038 myFax version 229 logs sensitive information in the export log module which allows any user to access critical information. Myfax150 Firmware No fix yet Fix from $1,6002021-07-07 HIGH 7.5 CVE-2021-35299 Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows attackers to obtain sensitive information via email connection configuration probing. Zammad after 4.0.0 Fix from $1,9502021-06-28 MEDIUM 5.5 CVE-2021-25420 Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi pass… Galaxy Watch Plugin 2.2.05.21033151+ Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-25421 Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi pas… Galaxy Watch 3 Plugin 2.2.09.21033151+ Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-25422 Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi pass… Watch Active Plugin 2.2.07.21033151+ Fix from $1,6002021-06-11 MEDIUM 5.5 CVE-2021-25423 Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi pas… Watch Active2 Plugin 2.2.08.21033151+ Fix from $1,6002021-06-11 HIGH 7.5 CVE-2020-15380 Brocade SANnav before version 2.1.1 logs account credentials at the ‘trace’ logging level. Sannav 2.1.1+ Fix from $1,9502021-06-09 HIGH 7.5 CVE-2021-22516 Insertion of Sensitive Information into Log File vulnerability in Micro Focus Secure API Manager (SAPIM) product, affecting version 2.0.0. The vulner… Secure Api Manager No fix yet Fix from $1,9502021-06-04 MEDIUM 5.5 CVE-2021-20191 A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when usi… Ansible 1.2.2 / 1.3.2+ Fix from $1,6002021-05-26 MEDIUM 5.5 CVE-2021-20178 A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using… Ansible 2.9.18+ Fix from $1,6002021-05-26 MEDIUM 5.3 CVE-2017-17675 BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack … Remedy Mid Tier Mitigation only Fix from $1,6002021-05-19 HIGH 8.8 CVE-2021-3528 A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake… Noobaa Operator 5.7.0+ Fix from $1,9502021-05-13 HIGH 7.5 CVE-2021-32074 HashiCorp vault-action (aka Vault GitHub Action) before 2.2.0 allows attackers to obtain sensitive information from log files because a multi-line se… Vault Action 2.2.0+ Fix from $1,9502021-05-07 MEDIUM 6.2 CVE-2021-20536 IBM Spectrum Protect Plus File Systems Agent 10.1.6 and 10.1.7 stores potentially sensitive information in log files that could be read by a local us… Spectrum Protect Plus Mitigation only Fix from $1,6002021-04-26 MEDIUM 6.5 CVE-2021-24024 A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and … Fortiadc after 5.3.7 Fix from $1,6002021-04-12 HIGH 7.5 CVE-2021-23924 An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files. Devolutions Server 2020.3+ Fix from $1,9502021-04-01 MEDIUM 5.5 CVE-2021-3447 A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod… Ansible 1.2.2 / 3.8.2+ Fix from $1,6002021-04-01 MEDIUM 5.5 CVE-2021-22184 An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that … GitLab 13.6.6 / 13.7.6+ Fix from $1,6002021-03-26 HIGH 7.8 CVE-2021-1442 A vulnerability in a diagnostic command for the Plug-and-Play (PnP) subsystem of Cisco IOS XE Software could allow an authenticated, local attacker t… Ios Xe Mitigation only Fix from $1,9502021-03-24 MEDIUM 6.5 CVE-2021-3167 In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs. Data Engineering Mitigation only Fix from $1,6002021-03-15 MEDIUM 5.1 CVE-2021-3034 An information exposure through log file vulnerability exists in Cortex XSOAR software where the secrets configured for the SAML single sign-on (SSO)… Cortex Xsoar Mitigation only Fix from $1,6002021-03-10 MEDIUM 6.5 CVE-2021-21361 The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment … Vagrant 0.6 / 3.0.0+ Fix from $1,6002021-03-09 MEDIUM 5.5 CVE-2021-25688 Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21.01.0 may… Pcoip Graphics Agent 20.10.0 / 21.01.0+ Fix from $1,6002021-02-11