Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2019-14268
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could…
Octopus Deploy
after 2019.7.2
MEDIUM 6.5
CVE-2019-13098
The user password via the registration form of TronLink Wallet 2.2.0 is stored in the log when the class CreateWalletTwoActivity is called. Other aut…
Wallet
No fix yet
HIGH 7.5
CVE-2019-13509
In Docker CE and EE before 18.09.8 (as well as Docker EE before 17.06.2-ee-23 and 18.x before 18.03.1-ee-10), Docker Engine in debug mode may sometim…
Docker
18.09.8+
MEDIUM 5.5
CVE-2019-10194
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…
Virtualization Manager
Mitigation only
MEDIUM 6.5
CVE-2018-19583
GitLab CE/EE, versions 8.0 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, would log access tokens in the Workhorse logs, perm…
GitLab
11.3.11 / 11.4.8+
MEDIUM 5.5
CVE-2019-4299
IBM Robotic Process Automation with Automation Anywhere 11 could allow a local user to obtain highly sensitive information from log files when debugg…
Robotic Process Automation With Automation Anywhere
11.0.0.5+
MEDIUM 5.3
CVE-2019-1622EPSS 79%
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to …
Data Center Network Manager
No fix yet
HIGH 7.8
CVE-2019-11271
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL…
Bosh
270.1.1+
CRITICAL 9.8
CVE-2019-3888
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…
Undertow
2.0.21+
HIGH 8.8
CVE-2019-9929
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
Cfengine
No fix yet
HIGH 8.1
CVE-2019-11336
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by using th…
Photo Sharing Plus
No fix yet
MEDIUM 5.9
CVE-2019-6158
An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear tex…
Xclarity Administrator
2.4.0+
HIGH 7.5
CVE-2019-11492
ProjectSend before r1070 writes user passwords to the server logs.
Projectsend
1070+
HIGH 7.5
CVE-2019-9734
Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under…
Aquarius Cms
after 4.3.5
HIGH 7.5
CVE-2019-9724
aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component.
Aquarius Cms
after 4.3.5
HIGH 7.5
CVE-2019-6157
In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web serv…
Flex System X240 M4 Firmware
5.30+
HIGH 7.8
CVE-2019-3891
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…
Satellite
No fix yet
HIGH 8.8
CVE-2019-9976
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users t…
H660rm Firmware
Mitigation only
HIGH 7.8
CVE-2019-0032
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authe…
Service Insight
18.1r1+
MEDIUM 5.5
CVE-2019-4143
The IBM Cloud Private Key Management Service (IBM Cloud Private 3.1.1 and 3.1.2) could allow a local user to obtain sensitive from the KMS plugin con…
Cloud Private
Mitigation only
HIGH 7.5
CVE-2018-16856
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.…
Openstack
2.0.2-5 / 3.0.1-0.20181009115732+
HIGH 7.8
CVE-2019-3830
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data t…
Openstack
after 2015.1.4
CRITICAL 9.8
CVE-2019-7612
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified …
Logstash
5.6.15 / 6.6.1+
HIGH 7.5
CVE-2018-19513
In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The…
Webgalamb
after 7.0
HIGH 7.0
CVE-2018-18466
An issue was discovered in SecurEnvoy SecurAccess 9.3.502. When put in Debug mode and used for RDP connections, the application stores the emergency …
Securaccess
Mitigation only
MEDIUM 5.5
CVE-2018-17499
Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unenc…
Passport
Mitigation only
MEDIUM 5.5
CVE-2019-3715
RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logged in plain text in the RSA A…
Archer Grc Platform
6.5+
HIGH 7.8
CVE-2019-3716
RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password may get logged in plain text i…
Archer Grc Platform
6.5.2.0+
HIGH 7.5
CVE-2019-0741EPSS 7%
An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT Java SDK Information Disclosu…
Java Software Development Kit
Patch available
MEDIUM 6.5
CVE-2019-8944
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticat…
Octopus Deploy
2019.1.8+