Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2019-18385 An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the include/makecvs.php?Event= s… Fs 210 Firmware No fix yet Fix from $1,9502019-10-23 HIGH 8.8 CVE-2019-11283 Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volu… Cf Deployment 2.0.3 / 12.2.0+ Fix from $1,9502019-10-23 CRITICAL 9.8 CVE-2019-17395 In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to atta… Rapidgator No fix yet Fix from $2,3002019-10-15 CRITICAL 9.8 CVE-2019-17394 In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be avai… Parent And Family No fix yet Fix from $2,3002019-10-15 CRITICAL 9.8 CVE-2019-17396 In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authentication, and may be available … Powerschool Mobile 1.1.8+ Fix from $2,3002019-10-15 CRITICAL 9.8 CVE-2019-17398 In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is stored in the log during auth… Dark Horse Comics No fix yet Fix from $2,3002019-10-15 CRITICAL 9.8 CVE-2019-17355 In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, and may be available to attacke… Orbitz No fix yet Fix from $2,3002019-10-15 CRITICAL 9.8 CVE-2019-17397 In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentication, and may be available t… Doordash after 11.5.2 Fix from $2,3002019-10-15 MEDIUM 5.5 CVE-2019-14858 A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar… Ansible Engine after 3.5.0 Fix from $1,6002019-10-14 HIGH 7.8 CVE-2019-14846 In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi… Ansible Engine 2.6.20 / 2.7.14+ Fix from $1,9502019-10-08 CRITICAL 9.8 CVE-2019-10212 A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o… Undertow 2.0.20+ Fix from $2,3002019-10-02 HIGH 7.5 CVE-2019-6656 BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerable versions of the client are … Big Ip Access Policy Manager 13.1.3 / 14.0.0.5+ Fix from $1,9502019-09-25 HIGH 7.7 CVE-2019-5532 VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability due to t… Vcenter Server No fix yet Fix from $1,9502019-09-18 HIGH 7.8 CVE-2019-3763 The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain an information exposure v… Rsa Identity Governance And Lifecycle Mitigation only Fix from $1,9502019-09-11 MEDIUM 5.3 CVE-2019-11465 An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted userna… Couchbase Server after 5.5.3 Fix from $1,6002019-09-10 MEDIUM 6.5 CVE-2019-11549 An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10… GitLab 11.8.9 / 11.9.10+ Fix from $1,6002019-09-09 MEDIUM 6.5 CVE-2019-11250 The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via log… Kubernetes 1.15.3+ Fix from $1,6002019-08-29 CRITICAL 9.8 CVE-2019-15294 An issue was discovered in Gallagher Command Centre 8.10 before 8.10.1092(MR2). Upon an upgrade, if a custom service account is in use and the visito… Command Centre 8.10.1092+ Fix from $2,3002019-08-28 MEDIUM 6.5 CVE-2019-15507 In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters… Server after 2019.7.6 Fix from $1,6002019-08-23 MEDIUM 6.5 CVE-2019-15508 In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables … Server after 2019.7.6 Fix from $1,6002019-08-23 MEDIUM 6.5 CVE-2019-13515 OSIsoft PI Web API 2018 and prior may allow disclosure of sensitive information. Pi Web Api after 2018 Fix from $1,6002019-08-15 MEDIUM 5.5 CVE-2018-20956 Swann SWWHD-INTCAM-HD devices leave the PSK in logs after a factory reset. NOTE: all affected customers were migrated by 2020-08-31. Swwhd Intcam Hd Firmware No fix yet Fix from $1,6002019-08-08 MEDIUM 6.5 CVE-2019-1953 A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a pas… Enterprise Network Function Virtualization Infrastructure 3.9.1+ Fix from $1,6002019-08-08 MEDIUM 5.5 CVE-2019-10367 Due to an incomplete fix of CVE-2019-10343, Jenkins Configuration as Code Plugin 1.26 and earlier did not properly apply masking to some values expec… Configuration As Code after 1.26 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2019-10370 Jenkins Mask Passwords Plugin 2.12.0 and earlier transmits globally configured passwords in plain text as part of the configuration form, potentially… Mask Passwords after 2.12.0 Fix from $1,6002019-08-07 MEDIUM 6.5 CVE-2016-10819 In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125). Cpanel 11.50.6.2 / 11.52.6.1+ Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2019-10345 Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export. Configuration As Code 1.20+ Fix from $1,6002019-07-31 MEDIUM 6.5 CVE-2019-10358 Jenkins Maven Integration Plugin 3.3 and earlier did not apply build log decorators to module builds, potentially revealing sensitive build variables… Maven after 3.3 Fix from $1,6002019-07-31 MEDIUM 5.5 CVE-2019-10364 Jenkins Amazon EC2 Plugin 1.43 and earlier wrote the beginning of private keys to the Jenkins system log. Ec2 after 1.43 Fix from $1,6002019-07-31 HIGH 7.5 CVE-2019-0202 The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i… Storm after 1.2.2 Fix from $1,9502019-07-26