Skip to main content

CWE archive

CWE-214 CVEs

Programmatic archive

24 CVEs tagged with CWE-2140 Critical, 7 High, 14 Medium, 3 Low, 0 Unrated.

CVE-2026-12139

Published Jul 21, 2026

Tanium addressed an information disclosure vulnerability in Connect.

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-9494

Published Jul 16, 2026

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-12250

Published Jul 5, 2026

Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. This is…

CVSS 7.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-41357

Published Apr 23, 2026

OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized process.env to child processes. Attackers can…

CVSS 2.0 · Low
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-40159

Published Apr 10, 2026

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied co…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33247

Published Mar 25, 2026

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentia…

CVSS 7.4 · High
evidence mentions
8
Buzz score
36.5
Vendor/product tagsBeta · best-effort

CVE-2025-59955

Published Jan 5, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information d…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5452

Published Nov 11, 2025

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the mali…

CVSS 6.6 · Medium

CVE-2025-53860

Published Oct 15, 2025

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48709

Published Aug 7, 2025

BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32987

Published Apr 15, 2025

Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

CVSS 6.0 · Medium

CVE-2024-39314

Published Jul 1, 2024

toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command l…

CVSS 4.7 · Medium

CVE-2024-4254

Published Jun 4, 2024

The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1742

Published Mar 22, 2024

Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36771

Published Jan 22, 2024

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32638

Published May 25, 2021

Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3869

Published Mar 28, 2019

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability t…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17957

Published Dec 26, 2018

The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to acc…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1