Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.1 CVE-2025-24884 kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used fo… Patch available Fix from $1,6002025-01-29 CRITICAL 9.4 CVE-2024-48852 Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access.… Mitigation only Fix from $2,3002025-01-29 MEDIUM 5.5 CVE-2025-0736 A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information,… Mitigation only Fix from $1,6002025-01-28 HIGH 7.5 CVE-2025-24169 A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to by… Safari 15.3 / 18.3+ Fix from $1,9502025-01-27 MEDIUM 5.5 CVE-2024-54519 The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive lo… macOS 14.7.2 / 15.2+ Fix from $1,6002025-01-27 MEDIUM 6.3 CVE-2025-24389 Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to … Mitigation only Fix from $1,6002025-01-27 MEDIUM 6.5 CVE-2023-38271 IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow… Cloud Pak System Mitigation only Fix from $1,6002025-01-25 HIGH 7.1 CVE-2025-24362 In some circumstances, debug artifacts uploaded by the CodeQL Action after a failed code scanning workflow run may contain the environment variables … Patch available Fix from $1,9502025-01-24 MEDIUM 5.5 CVE-2025-24457 In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs Youtrack 2024.3.55417+ Fix from $1,6002025-01-21 MEDIUM 5.5 CVE-2024-45091 IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensitive information in log files… Urbancode Deploy 7.0.5.25 / 7.1.2.21+ Fix from $1,6002025-01-21 MEDIUM 5.5 CVE-2024-11923 Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Formerly named Helpsystems One)… Mitigation only Fix from $1,6002025-01-18 MEDIUM 6.5 CVE-2024-12226 In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. … Mitigation only Fix from $1,6002025-01-16 MEDIUM 5.3 CVE-2024-55891 TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in c… TYPO3 Mitigation only Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21319 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21320 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21321 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21323 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21316 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21317 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 21h2 10.0.19044.5371 / 10.0.19045.5371+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2025-21318 Windows Kernel Memory Information Disclosure Vulnerability Windows 10 1507 10.0.10240.20890 / 10.0.14393.7699+ Fix from $1,6002025-01-14 MEDIUM 5.5 CVE-2024-40679 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive informat… Db2 Mitigation only Fix from $1,6002025-01-08 CRITICAL 9.3 CVE-2025-22275 iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive information from terminal commands by reading the /tm… Iterm2 3.5.11+ Fix from $2,3002025-01-03 HIGH 7.8 CVE-2024-12569 Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera … Mitigation only Fix from $1,9502024-12-19 MEDIUM 5.5 CVE-2024-54484 The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data. macOS 15.2+ Fix from $1,6002024-12-12 HIGH 8.5 CVE-2024-42407 Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Ope… Mitigation only Fix from $1,9502024-12-12 MEDIUM 5.5 CVE-2024-42196 HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs. Hcl Launch 7.0.5.25 / 7.1.2.21+ Fix from $1,6002024-12-06 MEDIUM 5.5 CVE-2024-47094 Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets … Checkmk Mitigation only Fix from $1,6002024-11-29 MEDIUM 5.5 CVE-2022-43937 Possible information exposure through log file vulnerability where sensitive fields are recorded in the debug-enabled logs when debugging is turned o… Brocade Sannav 2.2.2a+ Fix from $1,6002024-11-21 HIGH 7.5 CVE-2024-52940 AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The att… Mitigation only Fix from $1,9502024-11-18 MEDIUM 6.5 CVE-2024-11193 An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. Thi… Patch available Fix from $1,6002024-11-13