Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2025-62232 Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo… Apisix 3.14.0+ Fix from $1,9502025-10-31 MEDIUM 5.3 CVE-2025-58189 When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is… Go 1.24.8 / 1.25.2+ Fix from $1,6002025-10-29 HIGH 7.5 CVE-2025-11504 The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-co… Mitigation only Fix from $1,9502025-10-24 HIGH 7.5 CVE-2025-62513 OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein … Openbao 2.4.2+ Fix from $1,9502025-10-22 MEDIUM 5.3 CVE-2025-10486 The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly … Mitigation only Fix from $1,6002025-10-15 MEDIUM 6.2 CVE-2025-59258 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information loca… Windows Server 2012 10.0.17763.7919 / 10.0.20348.4294+ Fix from $1,6002025-10-14 MEDIUM 5.5 CVE-2025-59203 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 MEDIUM 5.5 CVE-2025-59197 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. Windows 10 1507 10.0.10240.21161 / 10.0.14393.8519+ Fix from $1,6002025-10-14 MEDIUM 5.5 CVE-2025-47979 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. Windows Server 2022 23h2 10.0.25398.1913+ Fix from $1,6002025-10-14 MEDIUM 5.7 CVE-2025-37727 Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing reques… Elasticsearch 8.18.8 / 8.19.5+ Fix from $1,6002025-10-10 MEDIUM 5.3 CVE-2025-10645 The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::lo… Mitigation only Fix from $1,6002025-10-07 MEDIUM 5.5 CVE-2025-36144 IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user. Watsonx.data Mitigation only Fix from $1,6002025-09-27 MEDIUM 5.3 CVE-2025-9985EPSS 11% The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 t… Mitigation only Fix from $1,6002025-09-26 HIGH 7.8 CVE-2025-34188 Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployme… Virtual Appliance Application 1.0.735 / 20.0.1330+ Fix from $1,9502025-09-19 HIGH 7.5 CVE-2025-34183 Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attacke… Eve X1 Server Firmware after 4.7.18.0 Fix from $1,9502025-09-16 MEDIUM 5.5 CVE-2025-43354 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchO… Ipados 26.0+ Fix from $1,6002025-09-15 MEDIUM 5.5 CVE-2025-43303 A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchO… Ipados 26.0+ Fix from $1,6002025-09-15 HIGH 7.5 CVE-2025-54376 Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by… Hoverfly 1.12.0+ Fix from $1,9502025-09-10 HIGH 7.8 CVE-2025-43888 Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A … Powerprotect Data Manager 19.21+ Fix from $1,9502025-09-10 MEDIUM 5.5 CVE-2025-10221 Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier… Axxon One after 2.0.4 Fix from $1,6002025-09-10 MEDIUM 6.5 CVE-2025-7445 Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs. Mitigation only Fix from $1,6002025-09-05 MEDIUM 5.5 CVE-2025-23261 NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially dis… Mitigation only Fix from $1,6002025-09-04 MEDIUM 6.5 CVE-2025-8663 Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This iss… Upkeeper Manager after 5.2.12 Fix from $1,6002025-09-03 HIGH 7.4 CVE-2025-41690 A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s even… Mitigation only Fix from $1,9502025-09-02 MEDIUM 5.5 CVE-2025-36133 IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potential… App Connect Enterprise Certified Containers Operands 12.15.0+ Fix from $1,6002025-09-01 MEDIUM 5.9 CVE-2025-57813 traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, su… Patch available Fix from $1,6002025-08-26 CRITICAL 9.3 CVE-2025-7426 Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated… Mitigation only Fix from $2,3002025-08-25 MEDIUM 6.5 CVE-2025-38745 Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backu… Openmanage Enterprise Mitigation only Fix from $1,6002025-08-14 MEDIUM 6.8 CVE-2025-8864 Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs Mitigation only Fix from $1,6002025-08-11 HIGH 7.8 CVE-2025-48709 BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could … Control M\/server Mitigation only Fix from $1,9502025-08-07