İçeriğe atla
Noroxi

CWE-117 · 123 kayıt

Improper Output Neutralization for Logs

Bu sınıftaki CVE’ler

123 kayıt

  • CVE-2026-17481
    39İzleyin

    IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution

    KritikCVSS 9,8İstismar yokEPSS %1

    ibm · documentation offline13 Ağu 2026

  • CVE-2024-0987
    39İzleyin

    Sichuan Yougou Technology KuERP log neutralization for logs

    KritikCVSS 9,8İstismar yokEPSS %1

    kuerp project · kuerp28 Oca 2024

  • CVE-2015-10011
    39İzleyin

    OpenDNS OpenResolve endpoints.py neutralization for logs

    KritikCVSS 9,8İstismar yokEPSS %1

    cisco · openresolve2 Oca 2023

  • CVE-2023-46321
    39İzleyin

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm222 Eki 2023

  • CVE-2023-46322
    39İzleyin

    iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.

    KritikCVSS 9,8İstismar yokEPSS %1

    iterm2 · iterm222 Eki 2023

  • CVE-2026-81695
    37İzleyin

    openssl_encrypt before 1.4.9 Terminal Injection via key_id

    KritikCVSS 9,3İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2026-81694
    37İzleyin

    verify-usb before 1.4.9 Output Injection via Unsanitized Filenames

    KritikCVSS 9,3İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2026-81696
    37İzleyin

    openssl_encrypt before 1.4.9 Terminal Injection via info Command

    KritikCVSS 9,3İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2026-74885
    37İzleyin

    openssl_encrypt before 1.4.0 Logging Bug and Race Condition

    KritikCVSS 9,3İstismar yokEPSS %0

    jahlives · openssl encrypt17 Ağu 2026

  • CVE-2024-47083
    35İzleyin

    Power Platform Terraform Provider has Improper Masking of Secrets in Logs

    YüksekCVSS 8,8İstismar yokEPSS %2

    microsoft · power platform terraform provider25 Eyl 2024

  • CVE-2024-25047
    34İzleyin

    IBM Cognos Analytics log injection

    YüksekCVSS 8,6İstismar yokEPSS %1

    ibm · cognos analytics2 May 2024

  • CVE-2023-4571
    34İzleyin

    Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)

    YüksekCVSS 8,6İstismar yokEPSS %0

    splunk · it service intelligence30 Ağu 2023

  • CVE-2022-22151
    32İzleyin

    CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versi

    YüksekCVSS 8,1İstismar yokEPSS %1

    yokogawa · centum cs 3000 firmware11 Mar 2022

  • CVE-2025-57564
    32İzleyin

    CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/inser

    YüksekCVSS 8,2İstismar yokEPSS %0

    7 Eki 2025

  • CVE-2019-14846
    31İzleyin

    In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG

    YüksekCVSS 7,8İstismar yokEPSS %1

    redhat · ansible engine8 Eki 2019

  • CVE-2026-10745
    31İzleyin

    Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injectio

    YüksekCVSS 7,9İstismar yokEPSS %0

    upkeeper solutions · upkeeper instant privilege access24 Haz 2026

  • CVE-2023-3997
    31İzleyin

    Unauthenticated Log Injection In Splunk SOAR

    YüksekCVSS 7,8İstismar yokEPSS %0

    splunk · soar31 Tem 2023

  • CVE-2020-25646
    30İzleyin

    A flaw was found in Ansible Collection community.crypto.

    YüksekCVSS 7,5İstismar yokEPSS %1

    ansible collections project · community.crypto29 Eki 2020

  • CVE-2024-9606
    30İzleyin

    Improper Output Neutralization for Logs in berriai/litellm

    YüksekCVSS 7,5İstismar yokEPSS %1

    litellm · litellm20 Mar 2025

  • CVE-2025-3942
    30İzleyin

    Improper Output Neutralization for Logs

    YüksekCVSS 7,5İstismar yokEPSS %0

    tridium · niagara22 May 2025

  • Yapscan's report receiver server vulnerable to path traversal and log injection

    YüksekCVSS 7,5İstismar yok

    Go · github.com/fkie-cad/yapscan29 Ara 2022

  • CVE-2024-0095
    28İzleyin

    NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by

    YüksekCVSS 7,2İstismar yokEPSS %1

    nvidia · triton inference server13 Haz 2024

  • CVE-2019-14864
    27İzleyin

    Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it

    OrtaCVSS 6,5İstismar yokEPSS %2

    redhat · ansible2 Oca 2020

  • CVE-2021-42250
    27İzleyin

    Possible log injection

    OrtaCVSS 6,5İstismar yokEPSS %2

    apache · superset17 Kas 2021

  • CVE-2026-34478
    27İzleyin

    Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility

    OrtaCVSS 6,9İstismar yokEPSS %1

    apache · log4j10 Nis 2026

Tüm zafiyet sınıfları