Total
1064 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-48635 | 1 Google | 1 Android | 2026-03-06 | N/A | 7.7 HIGH |
|
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
|
|||||
| CVE-2026-21786 | 2026-03-05 | N/A | 3.3 LOW | ||
|
HCL Sametime for iOS is impacted by a sensitive information disclosure. Hostnames information is written in application logs and certain URLs.
|
|||||
| CVE-2025-62879 | 1 Suse | 1 Rancher Backup And Restore Operator | 2026-03-05 | N/A | 6.8 MEDIUM |
|
A vulnerability has been identified within the Rancher Backup Operator, resulting in the leakage of S3 tokens (both accessKey and secretKey) into the rancher-backup-operator pod's logs.
|
|||||
| CVE-2026-1265 | 1 Ibm | 1 Infosphere Information Server | 2026-03-04 | N/A | 4.3 MEDIUM |
|
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.
|
|||||
| CVE-2026-25918 | 1 Rageagainstthepixel | 1 Unity-cli | 2026-02-28 | N/A | 5.5 MEDIUM |
|
unity-cli is a command line utility for the Unity Game Engine. Prior to 1.8.2 , the sign-package command in @rage-against-the-pixel/unity-cli logs sensitive credentials in plaintext when the --verbose flag is used. Command-line arguments including --email and --password are output via JSON.stringify without sanitization, exposing secrets to shell history, CI/CD logs, and log aggregation systems. This vulnerability is fixed in 1.8.2.
|
|||||
| CVE-2026-1292 | 1 Tanium | 1 Trends | 2026-02-27 | N/A | 6.5 MEDIUM |
|
Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
|
|||||
| CVE-2026-2350 | 1 Tanium | 1 Interact | 2026-02-27 | N/A | 6.5 MEDIUM |
|
Tanium addressed an insertion of sensitive information into log file vulnerability in Interact and TDS.
|
|||||
| CVE-2025-0976 | 3 Hitachi, Linux, Microsoft | 4 Configuration Manager, Ops Center Api Configuration Manager, Linux Kernel and 1 more | 2026-02-27 | N/A | 4.7 MEDIUM |
|
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.
|
|||||
| CVE-2026-27900 | 2026-02-27 | N/A | 5.0 MEDIUM | ||
|
The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackScript content, and object storage data in debug logs without redaction. Provider debug logging is not enabled by default. This issue is exposed when debug/provider logs are explicitly enabled (for example in local troubleshooting, CI/CD jobs, or centralized log collection). If enabled, sensitive values may be written to logs and then retained, shared, or exported beyond the ori ...
Show More |
|||||
| CVE-2025-5781 | 3 Hitachi, Linux, Microsoft | 5 Configuration Manager, Device Manager, Ops Center Api Configuration Manager and 2 more | 2026-02-27 | N/A | 5.2 MEDIUM |
|
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before 11.0.5-00; Hitachi Device Manager: from 8.4.1-00 before 8.6.5-00.
|
|||||
| CVE-2025-27555 | 1 Apache | 1 Airflow | 2026-02-24 | N/A | 6.5 MEDIUM |
|
Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see. When sensitive connection parameters were set via airflow CLI, values of those variables appeared in the audit log and were stored unencrypted in the Airflow database. While this risk is limited to users with audit log access, it is recommended to upgrade to Airflow 2.11.1 or a later version, which addresses this issue. Users w ...
Show More |
|||||
| CVE-2022-0338 | 1 Loguru Project | 1 Loguru | 2026-02-24 | 4.0 MEDIUM | 4.3 MEDIUM |
|
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
|
|||||
| CVE-2025-68675 | 1 Apache | 1 Airflow | 2026-02-24 | N/A | 7.5 HIGH |
|
In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These fields were not treated as sensitive by default and therefore were not automatically masked in log output. As a result, when such connections are rendered or printed to logs, proxy credentials embedded in these fields could be exposed.
Users are recommended to upgrade to 3.1.6 or later for Airflow 3, and 2.11.1 or later ...
Show More |
|||||
| CVE-2026-22778 | 1 Vllm | 1 Vllm | 2026-02-23 | N/A | 9.8 CRITICAL |
|
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.
|
|||||
| CVE-2026-24762 | 1 Rustfs | 1 Rustfs | 2026-02-23 | N/A | 7.5 HIGH |
|
RustFS is a distributed object storage system built in Rust. From versions alpha.13 to alpha.81, RustFS logs sensitive credential material (access key, secret key, session token) to application logs at INFO level. This results in credentials being recorded in plaintext in log output, which may be accessible to internal or external log consumers and could lead to compromise of sensitive credentials. This issue has been patched in version alpha.82.
|
|||||
| CVE-2026-20142 | 1 Splunk | 1 Splunk | 2026-02-23 | N/A | 6.8 MEDIUM |
|
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the RSA `accessKey` value from the [<u>Authentication.conf</u> ](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/configuration-file-reference/10.2.0-configuration-file-reference/authentication.conf)file, in plain text.
|
|||||
| CVE-2026-20144 | 1 Splunk | 2 Splunk, Splunk Cloud Platform | 2026-02-23 | N/A | 6.8 MEDIUM |
|
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.8, and 9.2.11, and Splunk Cloud Platform versions below 10.2.2510.0, 10.1.2507.11, 10.0.2503.9, and 9.3.2411.120, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the the Splunk _internal index could view the Security Assertion Markup Language (SAML) configurations for Attribute query requests (AQRs) or Authentication extensions in plain text within the conf.log file, depending on which feature ...
Show More |
|||||
| CVE-2022-4858 | 1 M-files | 1 M-files Server | 2026-02-23 | N/A | 4.4 MEDIUM |
|
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
|
|||||
| CVE-2021-41808 | 1 M-files | 1 M-files Server | 2026-02-23 | 1.9 LOW | 2.0 LOW |
|
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
|
|||||
| CVE-2026-2605 | 1 Tanium | 1 Tanos | 2026-02-20 | N/A | 5.3 MEDIUM |
|
Tanium addressed an insertion of sensitive information into log file vulnerability in TanOS.
|
|||||
| CVE-2024-25959 | 1 Dell | 1 Powerscale Onefs | 2026-02-20 | N/A | 7.9 HIGH |
|
Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to sensitive information disclosure, escalation of privileges.
|
|||||
| CVE-2023-32491 | 1 Dell | 1 Powerscale Onefs | 2026-02-20 | N/A | 6.3 MEDIUM |
|
Dell PowerScale OneFS 9.5.0.x, contains an insertion of sensitive information into log file vulnerability in SNMPv3. A low privileges user could potentially exploit this vulnerability, leading to information disclosure.
|
|||||
| CVE-2026-20138 | 1 Splunk | 1 Splunk | 2026-02-20 | N/A | 6.8 MEDIUM |
|
In Splunk Enterprise versions below 10.2.0, 10.0.2, 9.4.7, 9.3.9, and 9.2.11, a user of a Splunk Search Head Cluster (SHC) deployment who holds a role with access to the Splunk `_internal` index could view the `integrationKey`, `secretKey`, and `appSecretKey` secrets, generated by [Duo Two-Factor Authentication for Splunk Enterprise](https://duo.com/docs/splunk), in plain text.
|
|||||
| CVE-2026-25846 | 1 Jetbrains | 1 Youtrack | 2026-02-18 | N/A | 6.5 MEDIUM |
|
In JetBrains YouTrack before 2025.3.119033 access tokens could be exposed in Mailbox logs
|
|||||
| CVE-2026-25813 | 1 Prasklatechnology | 1 Placipy | 2026-02-18 | N/A | 7.5 HIGH |
|
PlaciPy is a placement management system designed for educational institutions. In version 1.0.0, The application logs highly sensitive data directly to console output without masking or redaction.
|
|||||
| CVE-2026-22038 | 1 Agpt | 1 Autogpt Platform | 2026-02-17 | N/A | 8.1 HIGH |
|
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.46, the AutoGPT platform's Stagehand integration blocks log API keys and authentication secrets in plaintext using logger.info() statements. This occurs in three separate block implementations (StagehandObserveBlock, StagehandActBlock, and StagehandExtractBlock) where the code explicitly calls api_key.get_secret_value ...
Show More |
|||||
| CVE-2025-11547 | 1 Axis | 1 Camera Station Pro | 2026-02-17 | N/A | 7.8 HIGH |
|
AXIS Camera Station Pro contained a flaw to perform a privilege escalation attack on the server as a non-admin user.
|
|||||
| CVE-2026-20646 | 1 Apple | 1 Macos | 2026-02-13 | N/A | 3.3 LOW |
|
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.
|
|||||
| CVE-2025-66411 | 1 Coder | 1 Coder | 2026-02-13 | N/A | 7.8 HIGH |
|
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values were logged in plaintext unsanitized. An attacker with limited local access to the Coder Workspace (VM, K8s Pod etc.) or a third-party system (SIEM, logging stack) could access those logs. This vulnerability is fixed in 2.26.5, 2.27.7, and 2.28.4.
|
|||||
| CVE-2026-20663 | 1 Apple | 2 Ipados, Iphone Os | 2026-02-12 | N/A | 3.3 LOW |
|
The issue was resolved by sanitizing logging. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An app may be able to enumerate a user's installed apps.
|
|||||
| CVE-2026-21222 | 1 Microsoft | 12 Windows 10 1607, Windows 10 1809, Windows 10 21h2 and 9 more | 2026-02-11 | N/A | 5.5 MEDIUM |
|
Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
|
|||||
| CVE-2026-1495 | 2026-02-10 | N/A | 6.5 MEDIUM | ||
|
The vulnerability, if exploited, could allow an attacker with Event Log Reader (S-1-5-32-573) privileges to obtain proxy details, including URL and proxy credentials, from the PI to CONNECT event log files. This could enable unauthorized access to the proxy server.
|
|||||
| CVE-2025-15332 | 1 Tanium | 1 Threat Response | 2026-02-10 | N/A | 4.9 MEDIUM |
|
Tanium addressed an information disclosure vulnerability in Threat Response.
|
|||||
| CVE-2026-22782 | 1 Rustfs | 1 Rustfs | 2026-02-09 | N/A | 7.5 HIGH |
|
RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and expected signature), which exposes the secret to log readers and enables forged RPC calls. In crates/ecstore/src/rpc/http_auth.rs, the invalid signature branch logs sensitive data. This log line includes secret and expected_signature, both derived from the shared HMAC key. Any invalidly signed request triggers this path. ...
Show More |
|||||
| CVE-2026-25211 | 2026-02-04 | N/A | 3.2 LOW | ||
|
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
|
|||||
| CVE-2026-1622 | 2026-02-04 | N/A | N/A | ||
|
Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files.
The "obfuscate_literals" option in the query logs does not redact error information, exposing unredacted data in the query log when a customer writes a query that fails. It can allow a user with legitimate access to the local log files to obtain information they are not authorised to see. If this user is al ...
Show More |
|||||
| CVE-2026-0519 | 1 Absolute | 1 Secure Access | 2026-02-02 | N/A | 3.4 LOW |
|
In Secure Access 12.70 and prior to 14.20, the logging
subsystem may write an unredacted authentication token to logs under
certain configurations. Any party with access to those logs could read
the token and reuse it to access an integrated system.
|
|||||
| CVE-2025-6391 | 1 Brocade | 1 Ascg | 2026-02-02 | N/A | 9.8 CRITICAL |
|
Brocade ASCG before 3.3.0 logs JSON
Web Tokens (JWT) in log files. An attacker with access to the log files
can withdraw the unencrypted tokens with security implications, such as
unauthorized access, session hijacking, and information disclosure.
|
|||||
| CVE-2025-13743 | 1 Docker | 1 Docker Desktop | 2026-01-30 | N/A | 7.5 HIGH |
|
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in exported diagnostics, especially when access denied errors occurred.
|
|||||
| CVE-2025-13925 | 1 Ibm | 1 Aspera Console | 2026-01-30 | N/A | 4.9 MEDIUM |
|
IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.
|
|||||