CVEs classified under CWE-214, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (24)
CVE-2026-12250 — CVSS 7.9 (high): Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus…
CVE-2020-36771 — CVSS 7.8 (high): CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local…
CVE-2021-3859 — CVSS 7.5 (high): A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an…
CVE-2026-76054: Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to…
CVE-2024-4254 — CVSS 7.1 (high): The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets…
CVE-2025-5452 — CVSS 6.6 (medium): A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to…
CVE-2026-61670 — CVSS 6.5 (medium): microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes…
CVE-2026-81684 — CVSS 6.2 (medium): In openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8, the desktop GUI passes the steganography password to the CLI child…
CVE-2025-1333 — CVSS 6.0 (medium): IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0…
CVE-2025-32987 — CVSS 6.0 (medium): Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line…
CVE-2026-102371: In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu…
CVE-2024-28799 — CVSS 5.6 (medium): IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data…
CVE-2026-92768 — CVSS 5.5 (medium): A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials…
CVE-2026-80158 — CVSS 5.5 (medium): A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply…
CVE-2026-65088 — CVSS 5.5 (medium): NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A…
CVE-2026-74873 — CVSS 5.5 (medium): openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system…
CVE-2026-9494 — CVSS 5.5 (medium): An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates…
CVE-2026-92747 — CVSS 5.0 (medium): A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose…
CVE-2026-92745 — CVSS 5.0 (medium): A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a…
CVE-2026-18915 — CVSS 5.0 (medium): Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute…
CVE-2025-53860 — CVSS 4.1 (medium): A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security…
CVE-2024-1742 — CVSS 3.8 (low): Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk…
CVE-2026-41357 — CVSS 3.3 (low): OpenClaw before 2026.3.31 contains an environment variable leakage vulnerability in SSH-based sandbox backends that pass unsanitized…