CWE-214 · 29 kayıt
Invocation of Process Using Visible Sensitive Information
Bu sınıftaki CVE’ler
29 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
34İzleyin | CVE-2026-74873İstismar yok | openssl_encrypt before 1.4.0 Password Exposure via CLI Argumentjahlives · openssl encrypt · CWE-214 | Yüksek8,7 | — | %0,3 | 17 Ağu 2026 |
31İzleyin | CVE-2020-36771İstismar yok | CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.cloudlinux · cagefs · CWE-214 | Yüksek7,8 | — | %0,5 | 22 Oca 2024 |
31İzleyin | CVE-2018-17957İstismar yok | yast2-rmt leaks database passwords in process listsuse · repository mirroring tool · CWE-214 | Yüksek7,8 | — | %0,4 | 26 Ara 2018 |
31İzleyin | CVE-2018-16837İstismar yok | Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.redhat · ansible engine · CWE-214 | Yüksek7,8 | — | %0,4 | 23 Eki 2018 |
31İzleyin | CVE-2026-12250İstismar yok | Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joinertubitak bilgem software technologies research institute · pardus domain joiner · CWE-214 | Yüksek7,9 | — | %0,2 | 5 Tem 2026 |
30İzleyin | CVE-2021-3859İstismar yok | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2.redhat · jboss enterprise application platform · CWE-214 | Yüksek7,5 | — | %1,6 | 26 Ağu 2022 |
30İzleyin | CVE-2024-28799İstismar yok | IBM QRadar Suite Software information disclosureibm · cloud pak for security · CWE-214 | Yüksek7,5 | — | %0,3 | 14 Ağu 2024 |
28İzleyin | CVE-2019-3869İstismar yok | When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variablredhat · ansible tower · CWE-214 | Yüksek7,2 | — | %1,3 | 28 Mar 2019 |
28İzleyin | CVE-2024-4254Kavram kanıtı | Secrets Exfiltration in gradio-app/gradiogradio project · gradio · CWE-214 | Yüksek7,1 | — | %0,5 | 4 Haz 2024 |
28İzleyin | CVE-2026-76054İstismar yok | Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to executeblack duck · blackduck-c-cpp · CWE-214 | Yüksek7,1 | — | %0,2 | 24 Ağu 2026 |
27İzleyin | CVE-2026-81684İstismar yok | openssl_encrypt before 1.4.9 Information Disclosure via Command Linejahlives · openssl encrypt · CWE-214 | Orta6,9 | — | %0,2 | 27 Ağu 2026 |
26İzleyin | CVE-2020-5422İstismar yok | UAA password may appear in BOSH System Metrics Server process argumentscloud foundry · bosh system metrics server · CWE-214 | Orta6,5 | — | %0,9 | 2 Eki 2020 |
26İzleyin | CVE-2025-5452İstismar yok | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potaxis · axis os · CWE-214 | Orta6,6 | — | %0,3 | 11 Kas 2025 |
26İzleyin | CVE-2025-1333İstismar yok | IBM MQ Operator information disclosureibm · mq operator · CWE-214 | Orta6,5 | — | %0,3 | 1 May 2025 |
26İzleyin | CVE-2026-61670İstismar yok | microsandbox: Secret values exposed in world-readable process argumentssuperradcompany · microsandbox · CWE-214 | Orta6,5 | — | %0,1 | 18 Eyl 2026 |
24İzleyin | CVE-2025-32987İstismar yok | Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line inarctera · ediscovery platform · CWE-214 | Orta6,0 | — | %0,2 | 14 Nis 2025 |
22İzleyin | CVE-2026-65088İstismar yok | NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information.nvidia · nemoclaw · CWE-214 | Orta5,5 | — | %0,2 | 25 Ağu 2026 |
22İzleyin | CVE-2026-12139İstismar yok | Tanium addressed an information disclosure vulnerability in Connect.tanium · connect · CWE-214 | Orta5,5 | — | %0,2 | 21 Tem 2026 |
22İzleyin | CVE-2026-92768İstismar yok | Cockpit-machines: cockpit-machines: sensitive data exposure via command-line argumentsred hat · red hat enterprise linux 10 · CWE-214 | Orta5,5 | — | %0,1 | 18 Eyl 2026 |
22İzleyin | CVE-2026-80158İstismar yok | Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs anred hat · red hat ceph storage 5 · CWE-214 | Orta5,5 | — | %0,1 | 26 Ağu 2026 |
22İzleyin | CVE-2026-9494İstismar yok | ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Linecanonical · ubuntu-pro-client (ubuntu-advantage-tools) · CWE-214 | Orta5,5 | — | %0,1 | 16 Tem 2026 |
22İzleyin | CVE-2025-53860İstismar yok | F5OS-A FIPS HSM vulnerabilityf5 · f5os-a · CWE-214 | Orta5,6 | — | %0,1 | 15 Eki 2025 |
22İzleyin | CVE-2026-102371İstismar yok | wsl-pro-service: Ubuntu Pro token exposed via process command-line argumentscanonical · ubuntu pro for wsl · CWE-214 | Orta5,7 | — | — | 1 gün önce |
20İzleyin | CVE-2026-18915İstismar yok | Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-locktübi̇tak bi̇lgem software technologies research institute · eta-otp-lock · CWE-214 | Orta5,0 | — | %0,1 | 6 Ağu 2026 |
20İzleyin | CVE-2026-92745İstismar yok | Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process argumentsred hat · red hat enterprise linux 10 · CWE-214 | Orta5,0 | — | %0,1 | 18 Eyl 2026 |
- CVE-2026-7487334İzleyin
openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
YüksekCVSS 8,7İstismar yokEPSS %0jahlives · openssl encrypt17 Ağu 2026
- CVE-2020-3677131İzleyin
CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.
YüksekCVSS 7,8İstismar yokEPSS %0cloudlinux · cagefs22 Oca 2024
- CVE-2018-1795731İzleyin
yast2-rmt leaks database passwords in process list
YüksekCVSS 7,8İstismar yokEPSS %0suse · repository mirroring tool26 Ara 2018
- CVE-2018-1683731İzleyin
Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.
YüksekCVSS 7,8İstismar yokEPSS %0redhat · ansible engine23 Eki 2018
- CVE-2026-1225031İzleyin
Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner
YüksekCVSS 7,9İstismar yokEPSS %0tubitak bilgem software technologies research institute · pardus domain joiner5 Tem 2026
- CVE-2021-385930İzleyin
A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2.
YüksekCVSS 7,5İstismar yokEPSS %2redhat · jboss enterprise application platform26 Ağu 2022
- CVE-2024-2879930İzleyin
IBM QRadar Suite Software information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · cloud pak for security14 Ağu 2024
- CVE-2019-386928İzleyin
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variabl
YüksekCVSS 7,2İstismar yokEPSS %1redhat · ansible tower28 Mar 2019
- CVE-2024-425428İzleyin
Secrets Exfiltration in gradio-app/gradio
YüksekCVSS 7,1Kavram kanıtıEPSS %0gradio project · gradio4 Haz 2024
- CVE-2026-7605428İzleyin
Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute
YüksekCVSS 7,1İstismar yokEPSS %0black duck · blackduck-c-cpp24 Ağu 2026
- CVE-2026-8168427İzleyin
openssl_encrypt before 1.4.9 Information Disclosure via Command Line
OrtaCVSS 6,9İstismar yokEPSS %0jahlives · openssl encrypt27 Ağu 2026
- CVE-2020-542226İzleyin
UAA password may appear in BOSH System Metrics Server process arguments
OrtaCVSS 6,5İstismar yokEPSS %1cloud foundry · bosh system metrics server2 Eki 2020
- CVE-2025-545226İzleyin
A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to pot
OrtaCVSS 6,6İstismar yokEPSS %0axis · axis os11 Kas 2025
- CVE-2025-133326İzleyin
IBM MQ Operator information disclosure
OrtaCVSS 6,5İstismar yokEPSS %0ibm · mq operator1 May 2025
- CVE-2026-6167026İzleyin
microsandbox: Secret values exposed in world-readable process arguments
OrtaCVSS 6,5İstismar yokEPSS %0superradcompany · microsandbox18 Eyl 2026
- CVE-2025-3298724İzleyin
Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in
OrtaCVSS 6,0İstismar yokEPSS %0arctera · ediscovery platform14 Nis 2025
- CVE-2026-6508822İzleyin
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information.
OrtaCVSS 5,5İstismar yokEPSS %0nvidia · nemoclaw25 Ağu 2026
- CVE-2026-1213922İzleyin
Tanium addressed an information disclosure vulnerability in Connect.
OrtaCVSS 5,5İstismar yokEPSS %0tanium · connect21 Tem 2026
- CVE-2026-9276822İzleyin
Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments
OrtaCVSS 5,5İstismar yokEPSS %0red hat · red hat enterprise linux 1018 Eyl 2026
- CVE-2026-8015822İzleyin
Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs an
OrtaCVSS 5,5İstismar yokEPSS %0red hat · red hat ceph storage 526 Ağu 2026
- CVE-2026-949422İzleyin
ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line
OrtaCVSS 5,5İstismar yokEPSS %0canonical · ubuntu-pro-client (ubuntu-advantage-tools)16 Tem 2026
- CVE-2025-5386022İzleyin
F5OS-A FIPS HSM vulnerability
OrtaCVSS 5,6İstismar yokEPSS %0f5 · f5os-a15 Eki 2025
- CVE-2026-10237122İzleyin
wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments
OrtaCVSS 5,7İstismar yokcanonical · ubuntu pro for wsl1 gün önce
- CVE-2026-1891520İzleyin
Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
OrtaCVSS 5,0İstismar yokEPSS %0tübi̇tak bi̇lgem software technologies research institute · eta-otp-lock6 Ağu 2026
- CVE-2026-9274520İzleyin
Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments
OrtaCVSS 5,0İstismar yokEPSS %0red hat · red hat enterprise linux 1018 Eyl 2026