Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2018-7433 The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page. Security after 6.9.0 Fix from $1,9502018-03-02 CRITICAL 9.8 CVE-2017-7434 In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exceptio… Identity Manager 4.6+ Fix from $2,3002018-03-02 CRITICAL 9.8 CVE-2017-9278 The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this … Identity Manager 4.0.2.0+ Fix from $2,3002018-03-02 HIGH 8.1 CVE-2018-3609EPSS 21% A vulnerability in the Trend Micro InterScan Messaging Security Virtual Appliance 9.0 and 9.1 management portal could allow an unauthenticated user t… Interscan Messaging Security Virtual Appliance No fix yet Fix from $1,9502018-02-16 MEDIUM 6.5 CVE-2018-2372 A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL… Hana Extended Application Services Mitigation only Fix from $1,6002018-02-14 CRITICAL 9.8 CVE-2018-1000060 Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utili… Sensu Core 1.2.1+ Fix from $2,3002018-02-09 HIGH 7.8 CVE-2018-1000018 An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file. Ovirt Hosted Engine Setup 2.2.7+ Fix from $1,9502018-01-24 MEDIUM 5.9 CVE-2017-6139 In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client reque… Big Ip Access Policy Manager Mitigation only Fix from $1,6002017-12-21 HIGH 8.4 CVE-2017-8001 An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who … Emc Scaleio Mitigation only Fix from $1,9502017-11-28 CRITICAL 9.8 CVE-2017-7550 A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attac… Ansible 2.3.3 / 2.4.1+ Fix from $2,3002017-11-21 CRITICAL 9.8 CVE-2017-1000171 Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text. Mahara Mobile after 1.2.0 Fix from $2,3002017-11-03 CRITICAL 9.8 CVE-2017-15366 Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is… Ndoc after 7.4 Fix from $2,3002017-10-26 CRITICAL 9.8 CVE-2017-6165 In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 11.6.1 HF1… Big Ip Access Policy Manager Mitigation only Fix from $2,3002017-10-20 HIGH 7.5 CVE-2017-15572 In Redmine before 3.2.6 and 3.3.x before 3.3.3, remote attackers can obtain sensitive information (password reset tokens) by reading a Referer log, b… Debian Linux after 3.2.5 Fix from $1,9502017-10-18 MEDIUM 5.9 CVE-2017-0380 The rend_service_intro_established function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x bef… Tor after 0.2.8.14 Fix from $1,6002017-09-18 MEDIUM 6.5 CVE-2017-11134 An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence,… Heinekingmedia after 1.7.5 Fix from $1,6002017-08-01 MEDIUM 5.5 CVE-2015-3243 rsyslog uses weak permissions for generating log files, which allows local users to obtain sensitive information by reading files in /var/log/cron. Rsyslog Mitigation only Fix from $1,6002017-07-25 CRITICAL 9.8 CVE-2017-6709 A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c… Ultra Services Framework after 5.0.2 Fix from $2,3002017-07-06 CRITICAL 9.8 CVE-2017-9615 Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging… Moneyworks after 8.0.3 Fix from $2,3002017-06-26 MEDIUM 6.5 CVE-2017-3744 In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture … Integrated Management Module Firmware after 6.19 Fix from $1,6002017-06-20 MEDIUM 6.5 CVE-2016-10362 Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials. Output Plugin after 5.0.0 Fix from $1,6002017-06-16 CRITICAL 9.8 CVE-2017-4955 An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28… Cloud Foundry Elastic Runtime Mitigation only Fix from $2,3002017-06-13 HIGH 7.5 CVE-2016-6799 Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d()… Cordova after 5.2.2 Fix from $1,9502017-05-09 CRITICAL 9.8 CVE-2017-8074 On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. Thi… Tl Sg108e Firmware No fix yet Fix from $2,3002017-04-23 CRITICAL 9.8 CVE-2017-8075 On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affect… Tl Sg108e Firmware No fix yet Fix from $2,3002017-04-23 CRITICAL 9.8 CVE-2017-7214 An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notificat… Nova Patch available Fix from $2,3002017-03-21 MEDIUM 5.5 CVE-2016-9985 IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671. Cognos Business Intelligence Patch available Fix from $1,6002017-03-08 CRITICAL 9.8 CVE-2016-8233 Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form… Xclarity Administrator after 1.2.1 Fix from $2,3002017-03-01 HIGH 7.8 CVE-2017-5153 An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 i… Pi Coresight after 2016-r2 Fix from $1,9502017-02-13 HIGH 7.5 CVE-2016-9344 An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able t… Miineport E1 Firmware after 1.7 Fix from $1,9502017-02-13