Перейти к содержимому
Noroxi

CWE-117 · 123 записей

Improper Output Neutralization for Logs

CVE этого класса

123 записей

  • CVE-2026-17481
    39Наблюдать

    IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ibm · documentation offline13 авг. 2026 г.

  • CVE-2024-0987
    39Наблюдать

    Sichuan Yougou Technology KuERP log neutralization for logs

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    kuerp project · kuerp28 янв. 2024 г.

  • CVE-2015-10011
    39Наблюдать

    OpenDNS OpenResolve endpoints.py neutralization for logs

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cisco · openresolve2 янв. 2023 г.

  • CVE-2023-46322
    39Наблюдать

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    iterm2 · iterm222 окт. 2023 г.

  • CVE-2023-46321
    39Наблюдать

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    iterm2 · iterm222 окт. 2023 г.

  • CVE-2026-81694
    37Наблюдать

    verify-usb before 1.4.9 Output Injection via Unsanitized Filenames

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt27 авг. 2026 г.

  • CVE-2026-81696
    37Наблюдать

    openssl_encrypt before 1.4.9 Terminal Injection via info Command

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt27 авг. 2026 г.

  • CVE-2026-81695
    37Наблюдать

    openssl_encrypt before 1.4.9 Terminal Injection via key_id

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt27 авг. 2026 г.

  • CVE-2026-74885
    37Наблюдать

    openssl_encrypt before 1.4.0 Logging Bug and Race Condition

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt17 авг. 2026 г.

  • CVE-2024-47083
    35Наблюдать

    Power Platform Terraform Provider has Improper Masking of Secrets in Logs

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    microsoft · power platform terraform provider25 сент. 2024 г.

  • CVE-2024-25047
    34Наблюдать

    IBM Cognos Analytics log injection

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    ibm · cognos analytics2 мая 2024 г.

  • CVE-2023-4571
    34Наблюдать

    Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    splunk · it service intelligence30 авг. 2023 г.

  • CVE-2022-22151
    32Наблюдать

    CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versi

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    yokogawa · centum cs 3000 firmware11 мар. 2022 г.

  • CVE-2025-57564
    32Наблюдать

    CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/inser

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    7 окт. 2025 г.

  • CVE-2019-14846
    31Наблюдать

    In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    redhat · ansible engine8 окт. 2019 г.

  • CVE-2026-10745
    31Наблюдать

    Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injectio

    ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %

    upkeeper solutions · upkeeper instant privilege access24 июн. 2026 г.

  • CVE-2023-3997
    31Наблюдать

    Unauthenticated Log Injection In Splunk SOAR

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    splunk · soar31 июл. 2023 г.

  • CVE-2020-25646
    30Наблюдать

    A flaw was found in Ansible Collection community.crypto.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    ansible collections project · community.crypto29 окт. 2020 г.

  • CVE-2024-9606
    30Наблюдать

    Improper Output Neutralization for Logs in berriai/litellm

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    litellm · litellm20 мар. 2025 г.

  • CVE-2025-3942
    30Наблюдать

    Improper Output Neutralization for Logs

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    tridium · niagara22 мая 2025 г.

  • GHSA-9h6h-9g78-86f7
    30Наблюдать

    Yapscan's report receiver server vulnerable to path traversal and log injection

    ВысокаяCVSS 7,5Эксплойта нет

    Go · github.com/fkie-cad/yapscan29 дек. 2022 г.

  • CVE-2024-0095
    28Наблюдать

    NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    nvidia · triton inference server13 июн. 2024 г.

  • CVE-2019-14864
    27Наблюдать

    Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    redhat · ansible2 янв. 2020 г.

  • CVE-2021-42250
    27Наблюдать

    Possible log injection

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    apache · superset17 нояб. 2021 г.

  • CVE-2026-34478
    27Наблюдать

    Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility

    СредняяCVSS 6,9Эксплойта нетEPSS 1 %

    apache · log4j10 апр. 2026 г.

Все классы уязвимостей