İçeriğe atla
Noroxi

CWE-214 · 29 kayıt

Invocation of Process Using Visible Sensitive Information

Bu sınıftaki CVE’ler

29 kayıt

  • CVE-2026-74873
    34İzleyin

    openssl_encrypt before 1.4.0 Password Exposure via CLI Argument

    YüksekCVSS 8,7İstismar yokEPSS %0

    jahlives · openssl encrypt17 Ağu 2026

  • CVE-2020-36771
    31İzleyin

    CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument.

    YüksekCVSS 7,8İstismar yokEPSS %0

    cloudlinux · cagefs22 Oca 2024

  • CVE-2018-17957
    31İzleyin

    yast2-rmt leaks database passwords in process list

    YüksekCVSS 7,8İstismar yokEPSS %0

    suse · repository mirroring tool26 Ara 2018

  • CVE-2018-16837
    31İzleyin

    Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen.

    YüksekCVSS 7,8İstismar yokEPSS %0

    redhat · ansible engine23 Eki 2018

  • CVE-2026-12250
    31İzleyin

    Sensitive Data Exposure in TUBITAK BILGEM's Pardus Domain Joiner

    YüksekCVSS 7,9İstismar yokEPSS %0

    tubitak bilgem software technologies research institute · pardus domain joiner5 Tem 2026

  • CVE-2021-3859
    30İzleyin

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2.

    YüksekCVSS 7,5İstismar yokEPSS %2

    redhat · jboss enterprise application platform26 Ağu 2022

  • CVE-2024-28799
    30İzleyin

    IBM QRadar Suite Software information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · cloud pak for security14 Ağu 2024

  • CVE-2019-3869
    28İzleyin

    When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variabl

    YüksekCVSS 7,2İstismar yokEPSS %1

    redhat · ansible tower28 Mar 2019

  • CVE-2024-4254
    28İzleyin

    Secrets Exfiltration in gradio-app/gradio

    YüksekCVSS 7,1Kavram kanıtıEPSS %0

    gradio project · gradio4 Haz 2024

  • CVE-2026-76054
    28İzleyin

    Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute

    YüksekCVSS 7,1İstismar yokEPSS %0

    black duck · blackduck-c-cpp24 Ağu 2026

  • CVE-2026-81684
    27İzleyin

    openssl_encrypt before 1.4.9 Information Disclosure via Command Line

    OrtaCVSS 6,9İstismar yokEPSS %0

    jahlives · openssl encrypt27 Ağu 2026

  • CVE-2020-5422
    26İzleyin

    UAA password may appear in BOSH System Metrics Server process arguments

    OrtaCVSS 6,5İstismar yokEPSS %1

    cloud foundry · bosh system metrics server2 Eki 2020

  • CVE-2025-5452
    26İzleyin

    A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to pot

    OrtaCVSS 6,6İstismar yokEPSS %0

    axis · axis os11 Kas 2025

  • CVE-2025-1333
    26İzleyin

    IBM MQ Operator information disclosure

    OrtaCVSS 6,5İstismar yokEPSS %0

    ibm · mq operator1 May 2025

  • CVE-2026-61670
    26İzleyin

    microsandbox: Secret values exposed in world-readable process arguments

    OrtaCVSS 6,5İstismar yokEPSS %0

    superradcompany · microsandbox18 Eyl 2026

  • CVE-2025-32987
    24İzleyin

    Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in

    OrtaCVSS 6,0İstismar yokEPSS %0

    arctera · ediscovery platform14 Nis 2025

  • CVE-2026-65088
    22İzleyin

    NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information.

    OrtaCVSS 5,5İstismar yokEPSS %0

    nvidia · nemoclaw25 Ağu 2026

  • CVE-2026-12139
    22İzleyin

    Tanium addressed an information disclosure vulnerability in Connect.

    OrtaCVSS 5,5İstismar yokEPSS %0

    tanium · connect21 Tem 2026

  • CVE-2026-92768
    22İzleyin

    Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments

    OrtaCVSS 5,5İstismar yokEPSS %0

    red hat · red hat enterprise linux 1018 Eyl 2026

  • CVE-2026-80158
    22İzleyin

    Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs an

    OrtaCVSS 5,5İstismar yokEPSS %0

    red hat · red hat ceph storage 526 Ağu 2026

  • CVE-2026-9494
    22İzleyin

    ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line

    OrtaCVSS 5,5İstismar yokEPSS %0

    canonical · ubuntu-pro-client (ubuntu-advantage-tools)16 Tem 2026

  • CVE-2025-53860
    22İzleyin

    F5OS-A FIPS HSM vulnerability

    OrtaCVSS 5,6İstismar yokEPSS %0

    f5 · f5os-a15 Eki 2025

  • CVE-2026-102371
    22İzleyin

    wsl-pro-service: Ubuntu Pro token exposed via process command-line arguments

    OrtaCVSS 5,7İstismar yok

    canonical · ubuntu pro for wsl1 gün önce

  • CVE-2026-18915
    20İzleyin

    Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock

    OrtaCVSS 5,0İstismar yokEPSS %0

    tübi̇tak bi̇lgem software technologies research institute · eta-otp-lock6 Ağu 2026

  • CVE-2026-92745
    20İzleyin

    Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments

    OrtaCVSS 5,0İstismar yokEPSS %0

    red hat · red hat enterprise linux 1018 Eyl 2026

Tüm zafiyet sınıfları