Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2026-8671 Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This … Avantra 25.3.0+ Fix from $1,9502026-05-22 HIGH 7.5 CVE-2026-44052 Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files t… Mitigation only Fix from $1,9502026-05-21 MEDIUM 6.5 CVE-2026-20239 In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.250… Splunk 10.0.5 / 10.0.2503.13+ Fix from $1,6002026-05-20 HIGH 7.6 CVE-2026-44516 Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module… Mitigation only Fix from $1,9502026-05-14 MEDIUM 5.5 CVE-2026-44479 Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (-… Vercel 52.0.1+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-41219 An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a… Big Ip Access Policy Manager after 17.5.1 Fix from $1,6002026-05-13 MEDIUM 5.3 CVE-2026-8200 When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generat… MongoDB 7.0.34 / 8.0.23+ Fix from $1,6002026-05-13 CRITICAL 9.8 CVE-2026-43992 JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, every MCP write tool (send_tokens, execute_contract, instantiate… Patch available Fix from $2,3002026-05-12 HIGH 7.5 CVE-2026-28987 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequ… Ipados 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 7.5 CVE-2026-28943 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequ… Ipados 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 HIGH 8.8 CVE-2026-28923 A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A mal… macOS 14.8.7 / 15.7.7+ Fix from $1,9502026-05-11 MEDIUM 6.5 CVE-2026-43826 The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920… Apache Airflow Providers Opensearch 1.9.1+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-41018 The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:… Apache Airflow Providers Elasticsearch 6.5.3+ Fix from $1,6002026-05-11 MEDIUM 5.3 CVE-2026-41495 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.11, when n8n… N8n Mcp 2.47.11+ Fix from $1,6002026-05-08 HIGH 8.3 CVE-2024-30151 HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthoriz… Bigfix Service Management Mitigation only Fix from $1,9502026-05-06 MEDIUM 5.9 CVE-2026-7824 An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is enabled, the application inadve… Mitigation only Fix from $1,6002026-05-05 HIGH 7.5 CVE-2025-67223 The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a pu… Mitigation only Fix from $1,9502026-04-28 MEDIUM 5.3 CVE-2026-41182 LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScript SDK and version 0.7.31 of … Mitigation only Fix from $1,6002026-04-23 HIGH 8.7 CVE-2026-40945 Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in … Mitigation only Fix from $1,9502026-04-21 MEDIUM 5.7 CVE-2026-23775 Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release versi… Data Domain Operating System 8.3.1.20 / 8.6.0.0+ Fix from $1,6002026-04-17 MEDIUM 6.6 CVE-2025-43937 Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attac… Powerscale Onefs 9.5.1.5 / 9.7.1.10+ Fix from $1,6002026-04-16 HIGH 7.5 CVE-2026-31987 JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that… Airflow 3.2.0+ Fix from $1,9502026-04-16 HIGH 7.2 CVE-2026-20205 In Splunk MCP Server app versions below 1.0.3 , a user who holds a role with access to the Splunk `_internal` index or possesses the high-privilege c… Mitigation only Fix from $1,9502026-04-15 MEDIUM 5.5 CVE-2026-32217 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.9060 / 10.0.17763.8644+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32218 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 21h2 10.0.19044.7184 / 10.0.19045.7184+ Fix from $1,6002026-04-14 MEDIUM 5.5 CVE-2026-32215 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1809 10.0.17763.8644 / 10.0.19044.7184+ Fix from $1,6002026-04-14 HIGH 8.5 CVE-2026-0207 A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions. No fix yet Fix from $1,9502026-04-14 MEDIUM 5.0 CVE-2026-2401 CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Adm… Powerchute Serial Shutdown 1.5+ Fix from $1,6002026-04-14 HIGH 7.5 CVE-2025-66236 Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to … Airflow 3.2.0+ Fix from $1,9502026-04-13 HIGH 7.5 CVE-2026-34487 Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet… Tomcat 9.0.117 / 10.1.54+ Fix from $1,9502026-04-09