CWE-117 · 123 записей
Improper Output Neutralization for Logs
CVE этого класса
123 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-17481Эксплойта нет | IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code executionibm · documentation offline · CWE-117 | Критическая9,8 | — | 0,9 % | 13 авг. 2026 г. |
39Наблюдать | CVE-2024-0987Эксплойта нет | Sichuan Yougou Technology KuERP log neutralization for logskuerp project · kuerp · CWE-117 | Критическая9,8 | — | 0,9 % | 28 янв. 2024 г. |
39Наблюдать | CVE-2015-10011Эксплойта нет | OpenDNS OpenResolve endpoints.py neutralization for logscisco · openresolve · CWE-117 | Критическая9,8 | — | 0,9 % | 2 янв. 2023 г. |
39Наблюдать | CVE-2023-46322Эксплойта нет | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.iterm2 · iterm2 · CWE-117 | Критическая9,8 | — | 0,7 % | 22 окт. 2023 г. |
39Наблюдать | CVE-2023-46321Эксплойта нет | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.iterm2 · iterm2 · CWE-117 | Критическая9,8 | — | 0,7 % | 22 окт. 2023 г. |
37Наблюдать | CVE-2026-81694Эксплойта нет | verify-usb before 1.4.9 Output Injection via Unsanitized Filenamesjahlives · openssl encrypt · CWE-117 | Критическая9,3 | — | 0,3 % | 27 авг. 2026 г. |
37Наблюдать | CVE-2026-81696Эксплойта нет | openssl_encrypt before 1.4.9 Terminal Injection via info Commandjahlives · openssl encrypt · CWE-117 | Критическая9,3 | — | 0,3 % | 27 авг. 2026 г. |
37Наблюдать | CVE-2026-81695Эксплойта нет | openssl_encrypt before 1.4.9 Terminal Injection via key_idjahlives · openssl encrypt · CWE-117 | Критическая9,3 | — | 0,3 % | 27 авг. 2026 г. |
37Наблюдать | CVE-2026-74885Эксплойта нет | openssl_encrypt before 1.4.0 Logging Bug and Race Conditionjahlives · openssl encrypt · CWE-117 | Критическая9,3 | — | 0,2 % | 17 авг. 2026 г. |
35Наблюдать | CVE-2024-47083Эксплойта нет | Power Platform Terraform Provider has Improper Masking of Secrets in Logsmicrosoft · power platform terraform provider · CWE-117 | Высокая8,8 | — | 1,6 % | 25 сент. 2024 г. |
34Наблюдать | CVE-2024-25047Эксплойта нет | IBM Cognos Analytics log injectionibm · cognos analytics · CWE-117 | Высокая8,6 | — | 0,6 % | 2 мая 2024 г. |
34Наблюдать | CVE-2023-4571Эксплойта нет | Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)splunk · it service intelligence · CWE-117 | Высокая8,6 | — | 0,3 % | 30 авг. 2023 г. |
32Наблюдать | CVE-2022-22151Эксплойта нет | CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versiyokogawa · centum cs 3000 firmware · CWE-117 | Высокая8,1 | — | 0,8 % | 11 мар. 2022 г. |
32Наблюдать | CVE-2025-57564Эксплойта нет | CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/inserCWE-117 | Высокая8,2 | — | 0,4 % | 7 окт. 2025 г. |
31Наблюдать | CVE-2019-14846Эксплойта нет | In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG redhat · ansible engine · CWE-117 | Высокая7,8 | — | 0,5 % | 8 окт. 2019 г. |
31Наблюдать | CVE-2026-10745Эксплойта нет | Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injectioupkeeper solutions · upkeeper instant privilege access · CWE-117 | Высокая7,9 | — | 0,4 % | 24 июн. 2026 г. |
31Наблюдать | CVE-2023-3997Эксплойта нет | Unauthenticated Log Injection In Splunk SOARsplunk · soar · CWE-117 | Высокая7,8 | — | 0,3 % | 31 июл. 2023 г. |
30Наблюдать | CVE-2020-25646Эксплойта нет | A flaw was found in Ansible Collection community.crypto.ansible collections project · community.crypto · CWE-117 | Высокая7,5 | — | 1,4 % | 29 окт. 2020 г. |
30Наблюдать | CVE-2024-9606Эксплойта нет | Improper Output Neutralization for Logs in berriai/litellmlitellm · litellm · CWE-117 | Высокая7,5 | — | 0,8 % | 20 мар. 2025 г. |
30Наблюдать | CVE-2025-3942Эксплойта нет | Improper Output Neutralization for Logstridium · niagara · CWE-117 | Высокая7,5 | — | 0,3 % | 22 мая 2025 г. |
30Наблюдать | GHSA-9h6h-9g78-86f7Эксплойта нет | Yapscan's report receiver server vulnerable to path traversal and log injectionGo · github.com/fkie-cad/yapscan · CWE-117 | Высокая7,5 | — | — | 29 дек. 2022 г. |
28Наблюдать | CVE-2024-0095Эксплойта нет | NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands bynvidia · triton inference server · CWE-117 | Высокая7,2 | — | 0,5 % | 13 июн. 2024 г. |
27Наблюдать | CVE-2019-14864Эксплойта нет | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it redhat · ansible · CWE-117 | Средняя6,5 | — | 1,9 % | 2 янв. 2020 г. |
27Наблюдать | CVE-2021-42250Эксплойта нет | Possible log injectionapache · superset · CWE-117 | Средняя6,5 | — | 1,8 % | 17 нояб. 2021 г. |
27Наблюдать | CVE-2026-34478Эксплойта нет | Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibilityapache · log4j · CWE-117 | Средняя6,9 | — | 1,2 % | 10 апр. 2026 г. |
- CVE-2026-1748139Наблюдать
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ibm · documentation offline13 авг. 2026 г.
- CVE-2024-098739Наблюдать
Sichuan Yougou Technology KuERP log neutralization for logs
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kuerp project · kuerp28 янв. 2024 г.
- CVE-2015-1001139Наблюдать
OpenDNS OpenResolve endpoints.py neutralization for logs
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cisco · openresolve2 янв. 2023 г.
- CVE-2023-4632239Наблюдать
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm222 окт. 2023 г.
- CVE-2023-4632139Наблюдать
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iterm2 · iterm222 окт. 2023 г.
- CVE-2026-8169437Наблюдать
verify-usb before 1.4.9 Output Injection via Unsanitized Filenames
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %jahlives · openssl encrypt27 авг. 2026 г.
- CVE-2026-8169637Наблюдать
openssl_encrypt before 1.4.9 Terminal Injection via info Command
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %jahlives · openssl encrypt27 авг. 2026 г.
- CVE-2026-8169537Наблюдать
openssl_encrypt before 1.4.9 Terminal Injection via key_id
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %jahlives · openssl encrypt27 авг. 2026 г.
- CVE-2026-7488537Наблюдать
openssl_encrypt before 1.4.0 Logging Bug and Race Condition
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %jahlives · openssl encrypt17 авг. 2026 г.
- CVE-2024-4708335Наблюдать
Power Platform Terraform Provider has Improper Masking of Secrets in Logs
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %microsoft · power platform terraform provider25 сент. 2024 г.
- CVE-2024-2504734Наблюдать
IBM Cognos Analytics log injection
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %ibm · cognos analytics2 мая 2024 г.
- CVE-2023-457134Наблюдать
Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %splunk · it service intelligence30 авг. 2023 г.
- CVE-2022-2215132Наблюдать
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versi
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %yokogawa · centum cs 3000 firmware11 мар. 2022 г.
- CVE-2025-5756432Наблюдать
CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/inser
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %7 окт. 2025 г.
- CVE-2019-1484631Наблюдать
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %redhat · ansible engine8 окт. 2019 г.
- CVE-2026-1074531Наблюдать
Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injectio
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %upkeeper solutions · upkeeper instant privilege access24 июн. 2026 г.
- CVE-2023-399731Наблюдать
Unauthenticated Log Injection In Splunk SOAR
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %splunk · soar31 июл. 2023 г.
- CVE-2020-2564630Наблюдать
A flaw was found in Ansible Collection community.crypto.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ansible collections project · community.crypto29 окт. 2020 г.
- CVE-2024-960630Наблюдать
Improper Output Neutralization for Logs in berriai/litellm
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %litellm · litellm20 мар. 2025 г.
- CVE-2025-394230Наблюдать
Improper Output Neutralization for Logs
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %tridium · niagara22 мая 2025 г.
- GHSA-9h6h-9g78-86f730Наблюдать
Yapscan's report receiver server vulnerable to path traversal and log injection
ВысокаяCVSS 7,5Эксплойта нетGo · github.com/fkie-cad/yapscan29 дек. 2022 г.
- CVE-2024-009528Наблюдать
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %nvidia · triton inference server13 июн. 2024 г.
- CVE-2019-1486427Наблюдать
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it
СредняяCVSS 6,5Эксплойта нетEPSS 2 %redhat · ansible2 янв. 2020 г.
- CVE-2021-4225027Наблюдать
Possible log injection
СредняяCVSS 6,5Эксплойта нетEPSS 2 %apache · superset17 нояб. 2021 г.
- CVE-2026-3447827Наблюдать
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
СредняяCVSS 6,9Эксплойта нетEPSS 1 %apache · log4j10 апр. 2026 г.