CWE-526 · 21 kayıt
Cleartext Storage of Sensitive Information in an Environment Variable
Bu sınıftaki CVE’ler
21 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2023-5720İstismar yok | Quarkus: build env information disclosure via gradle pluginquarkus · quarkus · CWE-526 | Yüksek7,5 | — | %0,8 | 15 Kas 2023 |
30İzleyin | CVE-2025-28381İstismar yok | A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all contaopenc3 · cosmos · CWE-526 | Yüksek7,5 | — | %0,5 | 13 Haz 2025 |
30İzleyin | CVE-2026-45370İstismar yok | python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injectionuniversal-tool-calling-protocol · python-utcp · CWE-526 | Yüksek7,7 | — | %0,4 | 14 May 2026 |
28İzleyin | CVE-2024-2700İstismar yok | Quarkus-core: leak of local configuration properties into quarkus applicationsred hat · hawtio 4.0.0 for red hat build of apache camel 4 · CWE-526 | Yüksek7,0 | — | %0,3 | 4 Nis 2024 |
27İzleyin | CVE-2024-4369İstismar yok | Cluster-image-registry-operator: exposes a secret via env variable in pod definition on azurered hat · red hat openshift container platform 4.14 · CWE-526 | Orta6,8 | — | %0,7 | 30 Nis 2024 |
27İzleyin | CVE-2023-43029İstismar yok | IBM Storage Virtualize vSphere Remote Plug-in information disclosureibm · storage virtualize plugin for vsphere · CWE-526 | Orta6,8 | — | %0,4 | 21 Mar 2025 |
27İzleyin | CVE-2026-76227İstismar yok | Renovate 42.68.1 before 42.96.3 Environment Variable Exposurerenovatebot · renovate · CWE-526 | Orta6,8 | — | %0,2 | 19 Ağu 2026 |
26İzleyin | CVE-2026-72648İstismar yok | Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosureelastic · elastic cloud on kubernetes · CWE-526 | Orta6,5 | — | %0,4 | 13 Ağu 2026 |
26İzleyin | CVE-2026-40153İstismar yok | PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Toolpraison · praisonaiagents · CWE-526 | Orta6,5 | — | %0,4 | 9 Nis 2026 |
26İzleyin | CVE-2025-36017İstismar yok | IBM Controller Information Disclosureibm · controller · CWE-526 | Orta6,5 | — | %0,3 | 8 Ara 2025 |
26İzleyin | CVE-2024-12604İstismar yok | Improper Authentication in Tapandsign Technologies Tap and Sign Apptapandsign · tap\&sign · CWE-526 | Orta6,5 | — | %0,2 | 10 Mar 2025 |
22İzleyin | CVE-2025-0985İstismar yok | IBM MQ information disclosureibm · mq · CWE-526 | Orta5,5 | — | %0,3 | 28 Şub 2025 |
22İzleyin | CVE-2023-47615İstismar yok | A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion Etelit · bgs5 firmware · CWE-526 | Orta5,5 | — | %0,2 | 9 Kas 2023 |
21İzleyin | CVE-2014-2377İstismar yok | Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variablesecava · integraxor · CWE-526 | Orta5,0 | — | %1,8 | 15 Eyl 2014 |
21İzleyin | CVE-2025-27899İstismar yok | Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windowsibm · db2 recovery expert · CWE-526 | Orta5,3 | — | %0,2 | 17 Şub 2026 |
19İzleyin | CVE-2024-11736İstismar yok | Org.keycloak:keycloak-quarkus-server: unrestricted admin use of system and environment variablesred hat · red hat build of keycloak 26.0 · CWE-526 | Orta4,9 | — | %0,8 | 14 Oca 2025 |
19İzleyin | CVE-2025-9162İstismar yok | Org.keycloak/keycloak-model-storage-service: variable injection into environment variableskeycloak · keycloak · CWE-526 | Orta4,9 | — | %0,5 | 21 Ağu 2025 |
19İzleyin | GHSA-w2wj-hw98-233hİstismar yok | Duplicate Advisory: Keycloak Potential Variable Reference in Model Storage ServicesMaven · org.keycloak:keycloak-model-storage-services · CWE-526 | Orta4,9 | — | — | 21 Ağu 2025 |
17İzleyin | CVE-2026-49377İstismar yok | In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parametersjetbrains · teamcity · CWE-526 | Orta4,3 | — | %0,9 | 29 May 2026 |
17İzleyin | CVE-2023-35931İstismar yok | Shescape potential environment variable exposure on Windows with CMDshescape project · shescape · CWE-526 | Orta4,3 | — | %0,8 | 23 Haz 2023 |
17İzleyin | CVE-2025-36105İstismar yok | IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerabilityibm · planning analytics advanced certified containers · CWE-526 | Orta4,4 | — | %0,1 | 10 Mar 2026 |
- CVE-2023-572030İzleyin
Quarkus: build env information disclosure via gradle plugin
YüksekCVSS 7,5İstismar yokEPSS %1quarkus · quarkus15 Kas 2023
- CVE-2025-2838130İzleyin
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all conta
YüksekCVSS 7,5İstismar yokEPSS %1openc3 · cosmos13 Haz 2025
- CVE-2026-4537030İzleyin
python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
YüksekCVSS 7,7İstismar yokEPSS %0universal-tool-calling-protocol · python-utcp14 May 2026
- CVE-2024-270028İzleyin
Quarkus-core: leak of local configuration properties into quarkus applications
YüksekCVSS 7,0İstismar yokEPSS %0red hat · hawtio 4.0.0 for red hat build of apache camel 44 Nis 2024
- CVE-2024-436927İzleyin
Cluster-image-registry-operator: exposes a secret via env variable in pod definition on azure
OrtaCVSS 6,8İstismar yokEPSS %1red hat · red hat openshift container platform 4.1430 Nis 2024
- CVE-2023-4302927İzleyin
IBM Storage Virtualize vSphere Remote Plug-in information disclosure
OrtaCVSS 6,8İstismar yokEPSS %0ibm · storage virtualize plugin for vsphere21 Mar 2025
- CVE-2026-7622727İzleyin
Renovate 42.68.1 before 42.96.3 Environment Variable Exposure
OrtaCVSS 6,8İstismar yokEPSS %0renovatebot · renovate19 Ağu 2026
- CVE-2026-7264826İzleyin
Cleartext Storage of Sensitive Information in an Environment Variable in Elastic Cloud on Kubernetes Leading to Information Disclosure
OrtaCVSS 6,5İstismar yokEPSS %0elastic · elastic cloud on kubernetes13 Ağu 2026
- CVE-2026-4015326İzleyin
PraisonAIAgents Affected by Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool
OrtaCVSS 6,5İstismar yokEPSS %0praison · praisonaiagents9 Nis 2026
- CVE-2025-3601726İzleyin
IBM Controller Information Disclosure
OrtaCVSS 6,5İstismar yokEPSS %0ibm · controller8 Ara 2025
- CVE-2024-1260426İzleyin
Improper Authentication in Tapandsign Technologies Tap and Sign App
OrtaCVSS 6,5İstismar yokEPSS %0tapandsign · tap\&sign10 Mar 2025
- CVE-2025-098522İzleyin
IBM MQ information disclosure
OrtaCVSS 5,5İstismar yokEPSS %0ibm · mq28 Şub 2025
- CVE-2023-4761522İzleyin
A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion E
OrtaCVSS 5,5İstismar yokEPSS %0telit · bgs5 firmware9 Kas 2023
- CVE-2014-237721İzleyin
Ecava IntegraXor SCADA Server Information Exposure Through Environmental Variables
OrtaCVSS 5,0İstismar yokEPSS %2ecava · integraxor15 Eyl 2014
- CVE-2025-2789921İzleyin
Multiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and Windows
OrtaCVSS 5,3İstismar yokEPSS %0ibm · db2 recovery expert17 Şub 2026
- CVE-2024-1173619İzleyin
Org.keycloak:keycloak-quarkus-server: unrestricted admin use of system and environment variables
OrtaCVSS 4,9İstismar yokEPSS %1red hat · red hat build of keycloak 26.014 Oca 2025
- CVE-2025-916219İzleyin
Org.keycloak/keycloak-model-storage-service: variable injection into environment variables
OrtaCVSS 4,9İstismar yokEPSS %0keycloak · keycloak21 Ağu 2025
- GHSA-w2wj-hw98-233h19İzleyin
Duplicate Advisory: Keycloak Potential Variable Reference in Model Storage Services
OrtaCVSS 4,9İstismar yokMaven · org.keycloak:keycloak-model-storage-services21 Ağu 2025
- CVE-2026-4937717İzleyin
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
OrtaCVSS 4,3İstismar yokEPSS %1jetbrains · teamcity29 May 2026
- CVE-2023-3593117İzleyin
Shescape potential environment variable exposure on Windows with CMD
OrtaCVSS 4,3İstismar yokEPSS %1shescape project · shescape23 Haz 2023
- CVE-2025-3610517İzleyin
IBM Planning Analytics Advanced Certified Containers is vulnerable to a sensitive information disclosure vulnerability
OrtaCVSS 4,4İstismar yokEPSS %0ibm · planning analytics advanced certified containers10 Mar 2026