Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
HIGH 7.5 CVE-2025-22246 Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. Cf Deployment 49.0.0 / 77.32.0+ Fix from $1,9502025-05-13 HIGH 7.6 CVE-2025-31213 A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Vent… Ipados 13.7.6 / 14.7.6+ Fix from $1,9502025-05-12 MEDIUM 5.2 CVE-2025-3911 Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of s… Mitigation only Fix from $1,6002025-04-29 MEDIUM 5.3 CVE-2025-4090 A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat. This vulnerability was fixed… Firefox 138.0+ Fix from $1,6002025-04-29 MEDIUM 6.5 CVE-2025-46432 In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs Teamcity 2025.03.1+ Fix from $1,6002025-04-25 HIGH 7.5 CVE-2025-2092 Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site auth… Checkmk 2.1.0+ Fix from $1,9502025-04-22 MEDIUM 5.5 CVE-2025-2300 Hitachi Ops Center Common Services within Hitachi Ops Center OVA contains an information exposure vulnerability. This issue affects Hitachi Ops Cente… Mitigation only Fix from $1,6002025-04-22 MEDIUM 5.9 CVE-2025-24651 Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-duplicator allows Retrieve Embe… Mitigation only Fix from $1,6002025-04-17 MEDIUM 6.5 CVE-2025-27391 Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th… Artemis 2.40.0+ Fix from $1,6002025-04-09 MEDIUM 6.5 CVE-2025-30677 Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka … Pulsar 3.0.11 / 3.3.6+ Fix from $1,6002025-04-09 MEDIUM 6.5 CVE-2025-25013 Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automat… Mitigation only Fix from $1,6002025-04-08 MEDIUM 5.7 CVE-2025-25002 Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent networ… Azure Local Cluster 2411.2+ Fix from $1,6002025-04-08 HIGH 8.2 CVE-2025-31479 canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to … Patch available Fix from $1,9502025-04-02 MEDIUM 5.3 CVE-2025-31788 Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all… Mitigation only Fix from $1,6002025-04-01 HIGH 7.5 CVE-2024-7577 IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files during new installation of the product. Infosphere Information Server 11.7.1+ Fix from $1,9502025-03-29 MEDIUM 5.5 CVE-2025-1998 IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.… Devops Deploy 7.1.2.22 / 7.2.3.15+ Fix from $1,6002025-03-27 MEDIUM 6.5 CVE-2025-31139 In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log Teamcity 2025.03+ Fix from $1,6002025-03-27 MEDIUM 5.5 CVE-2025-0273 HCL DevOps Deploy / HCL Launch stores potentially sensitive authentication token information in log files that could be read by a local user. Hcl Devops Deploy 7.1.2.22 / 7.2.3.15+ Fix from $1,6002025-03-27 MEDIUM 5.7 CVE-2025-20231 In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk C… Splunk 3.7.23 / 3.8.38+ Fix from $1,6002025-03-26 HIGH 7.6 CVE-2025-30205 kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function… Patch available Fix from $1,9502025-03-24 MEDIUM 6.5 CVE-2024-40585 An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 a… Fortimanager 6.2.12 / 6.4.13+ Fix from $1,6002025-03-14 MEDIUM 6.0 CVE-2025-2002 CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FT… Mitigation only Fix from $1,6002025-03-12 MEDIUM 6.5 CVE-2025-1296 Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in aud… Nomad 1.7.19 / 1.8.11+ Fix from $1,6002025-03-10 MEDIUM 5.2 CVE-2025-1696 A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via applica… Mitigation only Fix from $1,6002025-03-06 MEDIUM 6.4 CVE-2025-1979 Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged… Patch available Fix from $1,6002025-03-06 HIGH 7.5 CVE-2024-13818 The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for… Pie Register after 3.8.3.9 Fix from $1,9502025-02-21 HIGH 7.5 CVE-2025-1075 Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials … Checkmk 2.1.0+ Fix from $1,9502025-02-19 MEDIUM 5.1 CVE-2022-35202 A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private k… Mitigation only Fix from $1,6002025-02-11 HIGH 7.5 CVE-2024-57957 Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service… Harmonyos Mitigation only Fix from $1,9502025-02-06 HIGH 7.5 CVE-2025-24556 Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue aff… Mitigation only Fix from $1,9502025-02-03