Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.5 CVE-2026-4901 AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized… Control System 9.8.5+ Fix from $1,6002026-04-09 MEDIUM 5.5 CVE-2026-28261 Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of … Elastic Cloud Storage 4.1.0.3 / 4.2.0.1+ Fix from $1,6002026-04-08 MEDIUM 5.5 CVE-2026-4788 IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user. Tivoli Netcool\/impact 7.1.0.38+ Fix from $1,6002026-04-08 MEDIUM 5.5 CVE-2026-27315 Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh co… Cassandra 4.0.20+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-35185 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes … Haxiam No fix yet Fix from $1,9502026-04-06 MEDIUM 5.5 CVE-2019-25683 FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by… Filezilla Client No fix yet Fix from $1,6002026-04-05 MEDIUM 6.5 CVE-2026-4819 In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana. Flx 4.1.0+ Fix from $1,6002026-03-31 HIGH 7.5 CVE-2026-32982 OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error… Openclaw 2026.3.13+ Fix from $1,9502026-03-31 HIGH 7.3 CVE-2024-11604 Insertion of Sensitive Information into Log File vulnerability in the SCIM Driver module in OpenText IDM Driver and Extensions on Windows, Linux, 64 … Mitigation only Fix from $1,9502026-03-27 MEDIUM 5.5 CVE-2026-28868 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ… Ipados 14.8.5 / 15.7.5+ Fix from $1,6002026-03-25 MEDIUM 5.5 CVE-2026-20668 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequ… Ipados 14.8.5 / 15.7.5+ Fix from $1,6002026-03-25 MEDIUM 6.5 CVE-2026-32598 OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL —… Oneuptime 10.0.24+ Fix from $1,6002026-03-13 MEDIUM 6.5 CVE-2026-20165 In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.… Splunk 9.3.10 / 9.3.2411.124+ Fix from $1,6002026-03-11 MEDIUM 5.3 CVE-2025-70040 An issue pertaining to CWE-532: Insertion of Sensitive Information into Log File was discovered in LupinLin1 jimeng-web-mcp v2.1.2. This allows an at… Jimeng Web Mcp Server No fix yet Fix from $1,6002026-03-09 MEDIUM 6.5 CVE-2026-29184 Backstage is an open framework for building developer portals. Prior to version 3.1.4, a malicious scaffolder template can bypass the log redaction m… Backstage\/plugin Scaffolder Backend 3.1.4+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-24308 Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive inf… Zookeeper 3.8.6 / 3.9.5+ Fix from $1,9502026-03-07 MEDIUM 5.3 CVE-2026-1265 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file. Infosphere Information Server after 11.7.1.6 Fix from $1,6002026-03-03 HIGH 7.7 CVE-2025-48635 In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could l… Android Mitigation only Fix from $1,9502026-03-02 HIGH 7.7 CVE-2026-27900 The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object sto… Linode Provider 3.9.0+ Fix from $1,9502026-02-26 HIGH 7.5 CVE-2025-0976 Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Cent… Configuration Manager 8.6.1-00 / 11.0.4-00+ Fix from $1,9502026-02-25 MEDIUM 5.2 CVE-2025-5781 Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Sess… Configuration Manager 8.6.5-00 / 11.0.5-00+ Fix from $1,6002026-02-25 MEDIUM 6.5 CVE-2025-27555 Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which… Airflow 2.11.1+ Fix from $1,6002026-02-24 MEDIUM 5.3 CVE-2026-2605 Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS. Tanos 1.8.4.0249 / 1.8.5.0282+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-2350 Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS. Interact 3.2.196 / 3.5.102+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-1292 Tanium addressed an insertion of sensitive information into log file vulnerability in Trends. Trends 3.10.20 / 3.11.79+ Fix from $1,6002026-02-20 MEDIUM 6.5 CVE-2026-1495 The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and p… Mitigation only Fix from $1,6002026-02-10 MEDIUM 5.5 CVE-2026-21222 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. Windows 10 1607 10.0.14393.8868 / 10.0.17763.8389+ Fix from $1,6002026-02-10 HIGH 7.8 CVE-2025-11547 AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user. Camera Station Pro 6.13.55835+ Fix from $1,9502026-02-10 MEDIUM 5.5 CVE-2026-25918 unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs se… Unity Cli 1.8.2+ Fix from $1,6002026-02-09 HIGH 7.5 CVE-2026-25813 PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly… Placipy Mitigation only Fix from $1,9502026-02-09