CWE-214 · 29 записей
Invocation of Process Using Visible Sensitive Information
CVE этого класса
29 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2026-74873Эксплойта нет | openssl_encrypt before 1.4.0 Password Exposure via CLI Argumentjahlives · openssl encrypt · CWE-214 | Высокая8,7 | — | 0,3 % | 17 авг. 2026 г. |
31Наблюдать | CVE-2020-36771Эксплойта нет | CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.cloudlinux · cagefs · CWE-214 | Высокая7,8 | — | 0,5 % | 22 янв. 2024 г. |
31Наблюдать | CVE-2018-17957Эксплойта нет | yast2-rmt leaks database passwords in process listsuse · repository mirroring tool · CWE-214 | Высокая7,8 | — | 0,4 % | 26 дек. 2018 г. |
31Наблюдать | CVE-2018-16837Эксплойта нет | Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.redhat · ansible engine · CWE-214 | Высокая7,8 | — | 0,4 % | 23 окт. 2018 г. |
31Наблюдать | CVE-2026-12250Эксплойта нет | Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joinertubitak bilgem software technologies research institute · pardus domain joiner · CWE-214 | Высокая7,9 | — | 0,2 % | 5 июл. 2026 г. |
30Наблюдать | CVE-2021-3859Эксплойта нет | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2.redhat · jboss enterprise application platform · CWE-214 | Высокая7,5 | — | 1,6 % | 26 авг. 2022 г. |
30Наблюдать | CVE-2024-28799Эксплойта нет | IBM QRadar Suite Software information disclosureibm · cloud pak for security · CWE-214 | Высокая7,5 | — | 0,3 % | 14 авг. 2024 г. |
28Наблюдать | CVE-2019-3869Эксплойта нет | When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variablredhat · ansible tower · CWE-214 | Высокая7,2 | — | 1,3 % | 28 мар. 2019 г. |
28Наблюдать | CVE-2024-4254Proof of concept | Secrets Exfiltration in gradio-app/gradiogradio project · gradio · CWE-214 | Высокая7,1 | — | 0,5 % | 4 июн. 2024 г. |
28Наблюдать | CVE-2026-76054Эксплойта нет | Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to executeblack duck · blackduck-c-cpp · CWE-214 | Высокая7,1 | — | 0,2 % | 24 авг. 2026 г. |
27Наблюдать | CVE-2026-81684Эксплойта нет | openssl_encrypt before 1.4.9 Information Disclosure via Command Linejahlives · openssl encrypt · CWE-214 | Средняя6,9 | — | 0,2 % | 27 авг. 2026 г. |
26Наблюдать | CVE-2020-5422Эксплойта нет | UAA password may appear in BOSH System Metrics Server process argumentscloud foundry · bosh system metrics server · CWE-214 | Средняя6,5 | — | 0,9 % | 2 окт. 2020 г. |
26Наблюдать | CVE-2025-5452Эксплойта нет | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potaxis · axis os · CWE-214 | Средняя6,6 | — | 0,3 % | 11 нояб. 2025 г. |
26Наблюдать | CVE-2025-1333Эксплойта нет | IBM MQ Operator information disclosureibm · mq operator · CWE-214 | Средняя6,5 | — | 0,3 % | 1 мая 2025 г. |
26Наблюдать | CVE-2026-61670Эксплойта нет | microsandbox: Secret values exposed in world-readable process argumentssuperradcompany · microsandbox · CWE-214 | Средняя6,5 | — | 0,1 % | 18 сент. 2026 г. |
24Наблюдать | CVE-2025-32987Эксплойта нет | Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line inarctera · ediscovery platform · CWE-214 | Средняя6,0 | — | 0,2 % | 14 апр. 2025 г. |
22Наблюдать | CVE-2026-65088Эксплойта нет | NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information.nvidia · nemoclaw · CWE-214 | Средняя5,5 | — | 0,2 % | 25 авг. 2026 г. |
22Наблюдать | CVE-2026-12139Эксплойта нет | Tanium addressed an information disclosure vulnerability in Connect.tanium · connect · CWE-214 | Средняя5,5 | — | 0,2 % | 21 июл. 2026 г. |
22Наблюдать | CVE-2026-92768Эксплойта нет | Cockpit-machines: cockpit-machines: sensitive data exposure via command-line argumentsred hat · red hat enterprise linux 10 · CWE-214 | Средняя5,5 | — | 0,2 % | 18 сент. 2026 г. |
22Наблюдать | CVE-2026-80158Эксплойта нет | Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs anred hat · red hat ceph storage 5 · CWE-214 | Средняя5,5 | — | 0,1 % | 26 авг. 2026 г. |
22Наблюдать | CVE-2026-9494Эксплойта нет | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Linecanonical · ubuntu-pro-client (ubuntu-advantage-tools) · CWE-214 | Средняя5,5 | — | 0,1 % | 16 июл. 2026 г. |
22Наблюдать | CVE-2025-53860Эксплойта нет | F5OS-A FIPS HSM vulnerabilityf5 · f5os-a · CWE-214 | Средняя5,6 | — | 0,1 % | 15 окт. 2025 г. |
22Наблюдать | CVE-2026-102371Эксплойта нет | wsl-pro-service: Ubuntu Pro token exposed via process command-line argumentscanonical · ubuntu pro for wsl · CWE-214 | Средняя5,7 | — | 0,1 % | 29 сент. 2026 г. |
20Наблюдать | CVE-2026-92747Эксплойта нет | Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process listred hat · red hat enterprise linux 10 · CWE-214 | Средняя5,0 | — | 0,2 % | 18 сент. 2026 г. |
20Наблюдать | CVE-2026-18915Эксплойта нет | Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-locktübi̇tak bi̇lgem software technologies research institute · eta-otp-lock · CWE-214 | Средняя5,0 | — | 0,1 % | 6 авг. 2026 г. |
- CVE-2026-7487334Наблюдать
openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %jahlives · openssl encrypt17 авг. 2026 г.
- CVE-2020-3677131Наблюдать
CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %cloudlinux · cagefs22 янв. 2024 г.
- CVE-2018-1795731Наблюдать
yast2-rmt leaks database passwords in process list
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %suse · repository mirroring tool26 дек. 2018 г.
- CVE-2018-1683731Наблюдать
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %redhat · ansible engine23 окт. 2018 г.
- CVE-2026-1225031Наблюдать
Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %tubitak bilgem software technologies research institute · pardus domain joiner5 июл. 2026 г.
- CVE-2021-385930Наблюдать
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %redhat · jboss enterprise application platform26 авг. 2022 г.
- CVE-2024-2879930Наблюдать
IBM QRadar Suite Software information disclosure
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %ibm · cloud pak for security14 авг. 2024 г.
- CVE-2019-386928Наблюдать
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variabl
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %redhat · ansible tower28 мар. 2019 г.
- CVE-2024-425428Наблюдать
Secrets Exfiltration in gradio-app/gradio
ВысокаяCVSS 7,1Proof of conceptEPSS 0 %gradio project · gradio4 июн. 2024 г.
- CVE-2026-7605428Наблюдать
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %black duck · blackduck-c-cpp24 авг. 2026 г.
- CVE-2026-8168427Наблюдать
openssl_encrypt before 1.4.9 Information Disclosure via Command Line
СредняяCVSS 6,9Эксплойта нетEPSS 0 %jahlives · openssl encrypt27 авг. 2026 г.
- CVE-2020-542226Наблюдать
UAA password may appear in BOSH System Metrics Server process arguments
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cloud foundry · bosh system metrics server2 окт. 2020 г.
- CVE-2025-545226Наблюдать
A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to pot
СредняяCVSS 6,6Эксплойта нетEPSS 0 %axis · axis os11 нояб. 2025 г.
- CVE-2025-133326Наблюдать
IBM MQ Operator information disclosure
СредняяCVSS 6,5Эксплойта нетEPSS 0 %ibm · mq operator1 мая 2025 г.
- CVE-2026-6167026Наблюдать
microsandbox: Secret values exposed in world-readable process arguments
СредняяCVSS 6,5Эксплойта нетEPSS 0 %superradcompany · microsandbox18 сент. 2026 г.
- CVE-2025-3298724Наблюдать
Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in
СредняяCVSS 6,0Эксплойта нетEPSS 0 %arctera · ediscovery platform14 апр. 2025 г.
- CVE-2026-6508822Наблюдать
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %nvidia · nemoclaw25 авг. 2026 г.
- CVE-2026-1213922Наблюдать
Tanium addressed an information disclosure vulnerability in Connect.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %tanium · connect21 июл. 2026 г.
- CVE-2026-9276822Наблюдать
Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments
СредняяCVSS 5,5Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 1018 сент. 2026 г.
- CVE-2026-8015822Наблюдать
Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs an
СредняяCVSS 5,5Эксплойта нетEPSS 0 %red hat · red hat ceph storage 526 авг. 2026 г.
- CVE-2026-949422Наблюдать
ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
СредняяCVSS 5,5Эксплойта нетEPSS 0 %canonical · ubuntu-pro-client (ubuntu-advantage-tools)16 июл. 2026 г.
- CVE-2025-5386022Наблюдать
F5OS-A FIPS HSM vulnerability
СредняяCVSS 5,6Эксплойта нетEPSS 0 %f5 · f5os-a15 окт. 2025 г.
- CVE-2026-10237122Наблюдать
wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
СредняяCVSS 5,7Эксплойта нетEPSS 0 %canonical · ubuntu pro for wsl29 сент. 2026 г.
- CVE-2026-9274720Наблюдать
Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list
СредняяCVSS 5,0Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 1018 сент. 2026 г.
- CVE-2026-1891520Наблюдать
Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
СредняяCVSS 5,0Эксплойта нетEPSS 0 %tübi̇tak bi̇lgem software technologies research institute · eta-otp-lock6 авг. 2026 г.