Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.3 CVE-2018-3776 Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. Nextcloud Server 11.0.5 / 12.0.3+ Fix from $1,6002018-08-12 MEDIUM 5.5 CVE-2018-7754 The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address … Linux Kernel after 4.15 Fix from $1,6002018-08-10 MEDIUM 6.5 CVE-2018-1999036 An exposure of sensitive information vulnerability exists in Jenkins SSH Agent Plugin 1.15 and earlier in SSHAgentStepExecution.java that exposes the… Ssh Agent after 1.15 Fix from $1,6002018-08-01 MEDIUM 5.5 CVE-2017-2621 An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improp… Openstack 8.0.0+ Fix from $1,6002018-07-27 MEDIUM 6.6 CVE-2017-15113 ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change th… Virtualization 4.1.7.6+ Fix from $1,6002018-07-27 HIGH 7.8 CVE-2018-6971 VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vm… Horizon View Agents 7.5.1+ Fix from $1,9502018-07-25 CRITICAL 9.8 CVE-2018-11716EPSS 14% An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Cent… Manageengine Desktop Central 100230+ Fix from $2,3002018-07-16 CRITICAL 9.8 CVE-2018-11717EPSS 9% An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obta… Manageengine Desktop Central 100251+ Fix from $2,3002018-07-16 CRITICAL 9.8 CVE-2018-0042 Juniper Networks CSO versions prior to 4.0.0 may log passwords in log files leading to an information disclosure vulnerability. Contrail Service Orchestration 4.0.0+ Fix from $2,3002018-07-11 MEDIUM 5.3 CVE-2018-10889 A flaw was found in moodle before versions 3.5.1, 3.4.4, 3.3.7. No option existed to omit logs from data privacy exports, which may contain details o… Moodle 3.3.7 / 3.4.4+ Fix from $1,6002018-07-10 MEDIUM 5.9 CVE-2018-10855 Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect… Ansible Engine 2.4.5+ Fix from $1,6002018-07-03 CRITICAL 9.8 CVE-2018-1072 ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option… Enterprise Virtualization Manager 4.2.2+ Fix from $2,3002018-06-26 MEDIUM 6.5 CVE-2018-7682 Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains. Solutions Business Manager 11.4+ Fix from $1,6002018-06-22 HIGH 7.5 CVE-2018-7683 Micro Focus Solutions Business Manager versions prior to 11.4 might reveal certain sensitive information in server log files. Solutions Business Manager 11.4+ Fix from $1,9502018-06-21 HIGH 7.5 CVE-2018-12604EPSS 13% GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log. Greencms No fix yet Fix from $1,9502018-06-20 CRITICAL 9.8 CVE-2018-1117 ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou… Enterprise Virtualization 1.0.6+ Fix from $2,3002018-06-20 HIGH 7.8 CVE-2018-1075 ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one choo… Ovirt 4.2.3+ Fix from $1,9502018-06-12 HIGH 7.8 CVE-2018-0335 A vulnerability in the web portal authentication process of Cisco Prime Collaboration Provisioning could allow an unauthenticated, local attacker to … Prime Collaboration Mitigation only Fix from $1,9502018-06-07 HIGH 8.6 CVE-2016-10526 A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of th… Grunt Gh Pages 0.9.1+ Fix from $1,9502018-05-31 HIGH 8.8 CVE-2018-1241 Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, under certain conditions, may leak LDAP password in… Recoverpoint 5.1.1.3 / 5.1.2+ Fix from $1,9502018-05-29 CRITICAL 9.8 CVE-2018-11320 In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deploy… Octopus Server after 2018.5.1 Fix from $2,3002018-05-21 MEDIUM 5.5 CVE-2017-2592 python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could in… Ubuntu Linux after 3.23.0 Fix from $1,6002018-05-08 MEDIUM 5.3 CVE-2018-8719EPSS 16% An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not re… Wp Security Audit Log No fix yet Fix from $1,6002018-04-04 MEDIUM 6.5 CVE-2018-3817 When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information. Logstash 5.6.6 / 6.1.2+ Fix from $1,6002018-03-30 CRITICAL 10.0 CVE-2016-0898 MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup c… Pivotal Software Mysql Mitigation only Fix from $2,3002018-03-29 MEDIUM 5.3 CVE-2018-1349 The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration. Identity Manager after 4.6 Fix from $1,6002018-03-26 MEDIUM 5.3 CVE-2018-1350 The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration. Identity Manager after 4.6 Fix from $1,6002018-03-26 CRITICAL 9.8 CVE-2018-1000123 Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Fi… Ios Keychain after 2.0.0 Fix from $2,3002018-03-13 HIGH 7.4 CVE-2018-1000089 Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can resu… Django Anymail after 1.3 Fix from $1,9502018-03-13 HIGH 7.5 CVE-2018-7204 inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manage… File Manager after 5.0.0 Fix from $1,9502018-03-07