Перейти к содержимому
Noroxi

CWE-214 · 29 записей

Invocation of Process Using Visible Sensitive Information

CVE этого класса

29 записей

  • CVE-2026-74873
    34Наблюдать

    openssl_encrypt before 1.4.0 Password Exposure via CLI Argument

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt17 авг. 2026 г.

  • CVE-2020-36771
    31Наблюдать

    CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    cloudlinux · cagefs22 янв. 2024 г.

  • CVE-2018-17957
    31Наблюдать

    yast2-rmt leaks database passwords in process list

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    suse · repository mirroring tool26 дек. 2018 г.

  • CVE-2018-16837
    31Наблюдать

    Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    redhat · ansible engine23 окт. 2018 г.

  • CVE-2026-12250
    31Наблюдать

    Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner

    ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %

    tubitak bilgem software technologies research institute · pardus domain joiner5 июл. 2026 г.

  • CVE-2021-3859
    30Наблюдать

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    redhat · jboss enterprise application platform26 авг. 2022 г.

  • CVE-2024-28799
    30Наблюдать

    IBM QRadar Suite Software information disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · cloud pak for security14 авг. 2024 г.

  • CVE-2019-3869
    28Наблюдать

    When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variabl

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    redhat · ansible tower28 мар. 2019 г.

  • CVE-2024-4254
    28Наблюдать

    Secrets Exfiltration in gradio-app/gradio

    ВысокаяCVSS 7,1Proof of conceptEPSS 0 %

    gradio project · gradio4 июн. 2024 г.

  • CVE-2026-76054
    28Наблюдать

    Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    black duck · blackduck-c-cpp24 авг. 2026 г.

  • CVE-2026-81684
    27Наблюдать

    openssl_encrypt before 1.4.9 Information Disclosure via Command Line

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    jahlives · openssl encrypt27 авг. 2026 г.

  • CVE-2020-5422
    26Наблюдать

    UAA password may appear in BOSH System Metrics Server process arguments

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    cloud foundry · bosh system metrics server2 окт. 2020 г.

  • CVE-2025-5452
    26Наблюдать

    A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to pot

    СредняяCVSS 6,6Эксплойта нетEPSS 0 %

    axis · axis os11 нояб. 2025 г.

  • CVE-2025-1333
    26Наблюдать

    IBM MQ Operator information disclosure

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    ibm · mq operator1 мая 2025 г.

  • CVE-2026-61670
    26Наблюдать

    microsandbox: Secret values exposed in world-readable process arguments

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    superradcompany · microsandbox18 сент. 2026 г.

  • CVE-2025-32987
    24Наблюдать

    Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in

    СредняяCVSS 6,0Эксплойта нетEPSS 0 %

    arctera · ediscovery platform14 апр. 2025 г.

  • CVE-2026-65088
    22Наблюдать

    NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    nvidia · nemoclaw25 авг. 2026 г.

  • CVE-2026-12139
    22Наблюдать

    Tanium addressed an information disclosure vulnerability in Connect.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    tanium · connect21 июл. 2026 г.

  • CVE-2026-92768
    22Наблюдать

    Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    red hat · red hat enterprise linux 1018 сент. 2026 г.

  • CVE-2026-80158
    22Наблюдать

    Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs an

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    red hat · red hat ceph storage 526 авг. 2026 г.

  • CVE-2026-9494
    22Наблюдать

    ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    canonical · ubuntu-pro-client (ubuntu-advantage-tools)16 июл. 2026 г.

  • CVE-2025-53860
    22Наблюдать

    F5OS-A FIPS HSM vulnerability

    СредняяCVSS 5,6Эксплойта нетEPSS 0 %

    f5 · f5os-a15 окт. 2025 г.

  • CVE-2026-102371
    22Наблюдать

    wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments

    СредняяCVSS 5,7Эксплойта нетEPSS 0 %

    canonical · ubuntu pro for wsl29 сент. 2026 г.

  • CVE-2026-92747
    20Наблюдать

    Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list

    СредняяCVSS 5,0Эксплойта нетEPSS 0 %

    red hat · red hat enterprise linux 1018 сент. 2026 г.

  • CVE-2026-18915
    20Наблюдать

    Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock

    СредняяCVSS 5,0Эксплойта нетEPSS 0 %

    tübi̇tak bi̇lgem software technologies research institute · eta-otp-lock6 авг. 2026 г.

Все классы уязвимостей