Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2025-62232
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo…
Apisix
3.14.0+
MEDIUM 5.3
CVE-2025-58189
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is…
Go
1.24.8 / 1.25.2+
HIGH 7.5
CVE-2025-11504
The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-co…
Mitigation only
HIGH 7.5
CVE-2025-62513
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein …
Openbao
2.4.2+
MEDIUM 5.3
CVE-2025-10486
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly …
Mitigation only
MEDIUM 6.2
CVE-2025-59258
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information loca…
Windows Server 2012
10.0.17763.7919 / 10.0.20348.4294+
MEDIUM 5.5
CVE-2025-59203
Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-59197
Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-47979
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
Windows Server 2022 23h2
10.0.25398.1913+
MEDIUM 5.7
CVE-2025-37727
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing reques…
Elasticsearch
8.18.8 / 8.19.5+
MEDIUM 5.3
CVE-2025-10645
The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::lo…
Mitigation only
MEDIUM 5.5
CVE-2025-36144
IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.
Watsonx.data
Mitigation only
MEDIUM 5.3
CVE-2025-9985EPSS 11%
The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.7 t…
Mitigation only
HIGH 7.8
CVE-2025-34188
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (macOS/Linux client deployme…
Virtual Appliance Application
1.0.735 / 20.0.1330+
HIGH 7.5
CVE-2025-34183
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attacke…
Eve X1 Server Firmware
after 4.7.18.0
MEDIUM 5.5
CVE-2025-43354
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchO…
Ipados
26.0+
MEDIUM 5.5
CVE-2025-43303
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchO…
Ipados
26.0+
HIGH 7.5
CVE-2025-54376
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v2/ws/logs is not protected by…
Hoverfly
1.12.0+
HIGH 7.8
CVE-2025-43888
Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A …
Powerprotect Data Manager
19.21+
MEDIUM 5.5
CVE-2025-10221
Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier…
Axxon One
after 2.0.4
MEDIUM 6.5
CVE-2025-7445
Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
Mitigation only
MEDIUM 5.5
CVE-2025-23261
NVIDIA Cumulus Linux and NVOS products contain a vulnerability, where hashed user passwords are not properly suppressed in log files, potentially dis…
Mitigation only
MEDIUM 6.5
CVE-2025-8663
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This iss…
Upkeeper Manager
after 5.2.12
HIGH 7.4
CVE-2025-41690
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance) by viewing the device’s even…
Mitigation only
MEDIUM 5.5
CVE-2025-36133
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 through 12.0.14stores potential…
App Connect Enterprise Certified Containers Operands
12.15.0+
MEDIUM 5.9
CVE-2025-57813
traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists where sensitive information, su…
Patch available
CRITICAL 9.3
CVE-2025-7426
Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated…
Mitigation only
MEDIUM 6.5
CVE-2025-38745
Dell OpenManage Enterprise, versions 3.10, 4.0, 4.1, and 4.2, contains an Insertion of Sensitive Information into Log File vulnerability in the Backu…
Openmanage Enterprise
Mitigation only
MEDIUM 6.8
CVE-2025-8864
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
Mitigation only
HIGH 7.8
CVE-2025-48709
BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could …
Control M\/server
Mitigation only