Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.5 CVE-2026-25846 In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs Youtrack 2025.3.119033+ Fix from $1,6002026-02-09 HIGH 8.1 CVE-2026-22038 AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prio… Autogpt Platform 0.6.46+ Fix from $1,9502026-02-04 HIGH 7.5 CVE-2026-24762 RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access ke… Rustfs Mitigation only Fix from $1,9502026-02-03 CRITICAL 9.8 CVE-2026-22778 vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multim… Vllm 0.14.1+ Fix from $2,3002026-02-02 MEDIUM 5.0 CVE-2026-0936 An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local att… Mitigation only Fix from $1,6002026-01-29 MEDIUM 6.5 CVE-2025-59355 A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter s… Linkis 1.8.0+ Fix from $1,6002026-01-19 MEDIUM 5.5 CVE-2025-43508 A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. macOS Mitigation only Fix from $1,6002026-01-16 HIGH 7.5 CVE-2026-22782 RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log … Rustfs Patch available Fix from $1,9502026-01-16 HIGH 7.5 CVE-2025-68675 In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authe… Airflow 3.1.6+ Fix from $1,9502026-01-16 MEDIUM 6.2 CVE-2026-20818 Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. Windows Server 2016 10.0.14393.8783 / 10.0.17763.8276+ Fix from $1,6002026-01-13 MEDIUM 5.0 CVE-2026-22798 hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcomma… Hermes 0.9.1+ Fix from $1,6002026-01-12 MEDIUM 5.6 CVE-2025-68919 Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is… Mitigation only Fix from $1,6002025-12-24 MEDIUM 6.0 CVE-2025-66910 Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdm… Turms No fix yet Fix from $1,6002025-12-19 HIGH 7.5 CVE-2025-14437 The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the… Mitigation only Fix from $1,9502025-12-18 MEDIUM 5.5 CVE-2025-43475 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensit… Ipados 26.2+ Fix from $1,6002025-12-17 HIGH 7.5 CVE-2025-13743 Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaki… Docker Desktop 4.54.0+ Fix from $1,9502025-12-09 MEDIUM 6.6 CVE-2024-47570 An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; Fo… Fortiproxy 7.2.8 / 7.2.12+ Fix from $1,6002025-12-09 MEDIUM 6.5 CVE-2025-64650 IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. Storage Defender Resiliency Service after 2.0.18 Fix from $1,6002025-12-08 HIGH 8.7 CVE-2020-36876 ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated … No fix yet Fix from $1,9502025-12-05 MEDIUM 5.5 CVE-2025-14010 A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica… Community.general Patch available Fix from $1,6002025-12-04 MEDIUM 5.5 CVE-2025-66411 Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests… Coder 2.26.5 / 2.27.7+ Fix from $1,6002025-12-03 MEDIUM 5.3 CVE-2025-13611 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authe… GitLab 18.4.5 / 18.5.3+ Fix from $1,6002025-11-26 CRITICAL 9.0 CVE-2025-63729 An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SS… Sy Gpon 1110 Wdont Firmware No fix yet Fix from $2,3002025-11-25 MEDIUM 6.5 CVE-2025-11446 Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This iss… Upkeeper Manager 5.2.13.1+ Fix from $1,6002025-11-19 MEDIUM 6.5 CVE-2025-54971 An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all v… Fortiadc 7.4.3+ Fix from $1,6002025-11-18 MEDIUM 5.5 CVE-2025-62209 Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-11-11 MEDIUM 5.5 CVE-2025-62208 Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-11-11 MEDIUM 5.5 CVE-2025-12940 Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig I… Wax610y Firmware 11.8.0.10+ Fix from $1,6002025-11-11 CRITICAL 9.8 CVE-2025-11008 The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. Thi… Mitigation only Fix from $2,3002025-11-04 MEDIUM 5.5 CVE-2025-43426 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to … Ipados 26.1+ Fix from $1,6002025-11-04