A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.
Volume of CVEs assigned to CWE-214 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12250HIGH Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation.
This iss | Jul 5, 2026 | 7.9 | 36 | NO | NO |
CVE-2026-9494MEDIUM An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/l | Jul 16, 2026 | 5.5 | 28 | NO | NO |
CVE-2025-48709HIGH BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and u | Aug 7, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-3859HIGH A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks | Aug 26, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-16837HIGH Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a paramete | Oct 23, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-3869HIGH When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to | Mar 28, 2019 | 7.2 | 24 | NO | NO |
CVE-2018-17957HIGH The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to acce | Dec 26, 2018 | 7.8 | 24 | NO | NO |
CVE-2026-12139MEDIUM Tanium addressed an information disclosure vulnerability in Connect. | Jul 21, 2026 | 4.4 | 23 | NO | NO |
CVE-2026-33247MEDIUM NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credential | Mar 25, 2026 | 5.3 | 22 | NO | NO |
CVE-2025-5452MEDIUM A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malic | Nov 11, 2025 | 6.6 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.