CWE-117 · 123 kayıt
Improper Output Neutralization for Logs
Bu sınıftaki CVE’ler
123 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-17481İstismar yok | IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code executionibm · documentation offline · CWE-117 | Kritik9,8 | — | %0,9 | 13 Ağu 2026 |
39İzleyin | CVE-2024-0987İstismar yok | Sichuan Yougou Technology KuERP log neutralization for logskuerp project · kuerp · CWE-117 | Kritik9,8 | — | %0,9 | 28 Oca 2024 |
39İzleyin | CVE-2015-10011İstismar yok | OpenDNS OpenResolve endpoints.py neutralization for logscisco · openresolve · CWE-117 | Kritik9,8 | — | %0,9 | 2 Oca 2023 |
39İzleyin | CVE-2023-46321İstismar yok | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.iterm2 · iterm2 · CWE-117 | Kritik9,8 | — | %0,7 | 22 Eki 2023 |
39İzleyin | CVE-2023-46322İstismar yok | iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.iterm2 · iterm2 · CWE-117 | Kritik9,8 | — | %0,7 | 22 Eki 2023 |
37İzleyin | CVE-2026-81695İstismar yok | openssl_encrypt before 1.4.9 Terminal Injection via key_idjahlives · openssl encrypt · CWE-117 | Kritik9,3 | — | %0,3 | 27 Ağu 2026 |
37İzleyin | CVE-2026-81694İstismar yok | verify-usb before 1.4.9 Output Injection via Unsanitized Filenamesjahlives · openssl encrypt · CWE-117 | Kritik9,3 | — | %0,3 | 27 Ağu 2026 |
37İzleyin | CVE-2026-81696İstismar yok | openssl_encrypt before 1.4.9 Terminal Injection via info Commandjahlives · openssl encrypt · CWE-117 | Kritik9,3 | — | %0,3 | 27 Ağu 2026 |
37İzleyin | CVE-2026-74885İstismar yok | openssl_encrypt before 1.4.0 Logging Bug and Race Conditionjahlives · openssl encrypt · CWE-117 | Kritik9,3 | — | %0,2 | 17 Ağu 2026 |
35İzleyin | CVE-2024-47083İstismar yok | Power Platform Terraform Provider has Improper Masking of Secrets in Logsmicrosoft · power platform terraform provider · CWE-117 | Yüksek8,8 | — | %1,6 | 25 Eyl 2024 |
34İzleyin | CVE-2024-25047İstismar yok | IBM Cognos Analytics log injectionibm · cognos analytics · CWE-117 | Yüksek8,6 | — | %0,6 | 2 May 2024 |
34İzleyin | CVE-2023-4571İstismar yok | Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)splunk · it service intelligence · CWE-117 | Yüksek8,6 | — | %0,3 | 30 Ağu 2023 |
32İzleyin | CVE-2022-22151İstismar yok | CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versiyokogawa · centum cs 3000 firmware · CWE-117 | Yüksek8,1 | — | %0,8 | 11 Mar 2022 |
32İzleyin | CVE-2025-57564İstismar yok | CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/inserCWE-117 | Yüksek8,2 | — | %0,4 | 7 Eki 2025 |
31İzleyin | CVE-2019-14846İstismar yok | In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG redhat · ansible engine · CWE-117 | Yüksek7,8 | — | %0,5 | 8 Eki 2019 |
31İzleyin | CVE-2026-10745İstismar yok | Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injectioupkeeper solutions · upkeeper instant privilege access · CWE-117 | Yüksek7,9 | — | %0,4 | 24 Haz 2026 |
31İzleyin | CVE-2023-3997İstismar yok | Unauthenticated Log Injection In Splunk SOARsplunk · soar · CWE-117 | Yüksek7,8 | — | %0,3 | 31 Tem 2023 |
30İzleyin | CVE-2020-25646İstismar yok | A flaw was found in Ansible Collection community.crypto.ansible collections project · community.crypto · CWE-117 | Yüksek7,5 | — | %1,4 | 29 Eki 2020 |
30İzleyin | CVE-2024-9606İstismar yok | Improper Output Neutralization for Logs in berriai/litellmlitellm · litellm · CWE-117 | Yüksek7,5 | — | %0,8 | 20 Mar 2025 |
30İzleyin | CVE-2025-3942İstismar yok | Improper Output Neutralization for Logstridium · niagara · CWE-117 | Yüksek7,5 | — | %0,3 | 22 May 2025 |
30İzleyin | GHSA-9h6h-9g78-86f7İstismar yok | Yapscan's report receiver server vulnerable to path traversal and log injectionGo · github.com/fkie-cad/yapscan · CWE-117 | Yüksek7,5 | — | — | 29 Ara 2022 |
28İzleyin | CVE-2024-0095İstismar yok | NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands bynvidia · triton inference server · CWE-117 | Yüksek7,2 | — | %0,5 | 13 Haz 2024 |
27İzleyin | CVE-2019-14864İstismar yok | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it redhat · ansible · CWE-117 | Orta6,5 | — | %1,9 | 2 Oca 2020 |
27İzleyin | CVE-2021-42250İstismar yok | Possible log injectionapache · superset · CWE-117 | Orta6,5 | — | %1,8 | 17 Kas 2021 |
27İzleyin | CVE-2026-34478İstismar yok | Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibilityapache · log4j · CWE-117 | Orta6,9 | — | %1,2 | 10 Nis 2026 |
- CVE-2026-1748139İzleyin
IBM Documentation Offline is vulnerable to information disclosure, session forgery and remote code execution
KritikCVSS 9,8İstismar yokEPSS %1ibm · documentation offline13 Ağu 2026
- CVE-2024-098739İzleyin
Sichuan Yougou Technology KuERP log neutralization for logs
KritikCVSS 9,8İstismar yokEPSS %1kuerp project · kuerp28 Oca 2024
- CVE-2015-1001139İzleyin
OpenDNS OpenResolve endpoints.py neutralization for logs
KritikCVSS 9,8İstismar yokEPSS %1cisco · openresolve2 Oca 2023
- CVE-2023-4632139İzleyin
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs.
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm222 Eki 2023
- CVE-2023-4632239İzleyin
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs.
KritikCVSS 9,8İstismar yokEPSS %1iterm2 · iterm222 Eki 2023
- CVE-2026-8169537İzleyin
openssl_encrypt before 1.4.9 Terminal Injection via key_id
KritikCVSS 9,3İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2026-8169437İzleyin
verify-usb before 1.4.9 Output Injection via Unsanitized Filenames
KritikCVSS 9,3İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2026-8169637İzleyin
openssl_encrypt before 1.4.9 Terminal Injection via info Command
KritikCVSS 9,3İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2026-7488537İzleyin
openssl_encrypt before 1.4.0 Logging Bug and Race Condition
KritikCVSS 9,3İstismar yokEPSS %0jahlives · openssl encrypt17 Ağu 2026
- CVE-2024-4708335İzleyin
Power Platform Terraform Provider has Improper Masking of Secrets in Logs
YüksekCVSS 8,8İstismar yokEPSS %2microsoft · power platform terraform provider25 Eyl 2024
- CVE-2024-2504734İzleyin
IBM Cognos Analytics log injection
YüksekCVSS 8,6İstismar yokEPSS %1ibm · cognos analytics2 May 2024
- CVE-2023-457134İzleyin
Unauthenticated Log Injection in Splunk IT Service Intelligence (ITSI)
YüksekCVSS 8,6İstismar yokEPSS %0splunk · it service intelligence30 Ağu 2023
- CVE-2022-2215132İzleyin
CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: CENTUM CS 3000 versi
YüksekCVSS 8,1İstismar yokEPSS %1yokogawa · centum cs 3000 firmware11 Mar 2022
- CVE-2025-5756432İzleyin
CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/inser
YüksekCVSS 8,2İstismar yokEPSS %07 Eki 2025
- CVE-2019-1484631İzleyin
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG
YüksekCVSS 7,8İstismar yokEPSS %1redhat · ansible engine8 Eki 2019
- CVE-2026-1074531İzleyin
Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injectio
YüksekCVSS 7,9İstismar yokEPSS %0upkeeper solutions · upkeeper instant privilege access24 Haz 2026
- CVE-2023-399731İzleyin
Unauthenticated Log Injection In Splunk SOAR
YüksekCVSS 7,8İstismar yokEPSS %0splunk · soar31 Tem 2023
- CVE-2020-2564630İzleyin
A flaw was found in Ansible Collection community.crypto.
YüksekCVSS 7,5İstismar yokEPSS %1ansible collections project · community.crypto29 Eki 2020
- CVE-2024-960630İzleyin
Improper Output Neutralization for Logs in berriai/litellm
YüksekCVSS 7,5İstismar yokEPSS %1litellm · litellm20 Mar 2025
- CVE-2025-394230İzleyin
Improper Output Neutralization for Logs
YüksekCVSS 7,5İstismar yokEPSS %0tridium · niagara22 May 2025
- GHSA-9h6h-9g78-86f730İzleyin
Yapscan's report receiver server vulnerable to path traversal and log injection
YüksekCVSS 7,5İstismar yokGo · github.com/fkie-cad/yapscan29 Ara 2022
- CVE-2024-009528İzleyin
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by
YüksekCVSS 7,2İstismar yokEPSS %1nvidia · triton inference server13 Haz 2024
- CVE-2019-1486427İzleyin
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it
OrtaCVSS 6,5İstismar yokEPSS %2redhat · ansible2 Oca 2020
- CVE-2021-4225027İzleyin
Possible log injection
OrtaCVSS 6,5İstismar yokEPSS %2apache · superset17 Kas 2021
- CVE-2026-3447827İzleyin
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
OrtaCVSS 6,9İstismar yokEPSS %1apache · log4j10 Nis 2026