Description
A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.
Extended Description
Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as credentials, it might allow other users to launch an attack against the product or related resources.
CVE vulnerabilities with CWE-214 (30)
8.7
CVSS
HIGH
CVE-2026-74873
pub. 2026-08-17
7.9
CVSS
HIGH
CVE-2026-12250
pub. 2026-07-05
7.8
CVSS
HIGH
CVE-2020-36771
pub. 2024-01-22
7.8
CVSS
HIGH
CVE-2018-16837
pub. 2018-10-23
7.5
CVSS
HIGH
CVE-2021-3859
pub. 2022-08-26
7.4
CVSS
HIGH
CVE-2026-33247
pub. 2026-03-25
7.2
CVSS
HIGH
CVE-2019-3869
pub. 2019-03-28
7.1
CVSS
HIGH
CVE-2026-76054
pub. 2026-08-24
7.1
CVSS
HIGH
CVE-2024-4254
pub. 2024-06-04
6.9
CVSS
MEDIUM
CVE-2026-81684
pub. 2026-08-27
6.6
CVSS
MEDIUM
CVE-2025-5452
pub. 2025-11-11
6.5
CVSS
MEDIUM
CVE-2020-5422
pub. 2020-10-02
6.0
CVSS
MEDIUM
CVE-2025-1333
pub. 2025-05-01
6.0
CVSS
MEDIUM
CVE-2025-32987
pub. 2025-04-15
5.7
CVSS
MEDIUM
CVE-2025-59955
pub. 2026-01-05
5.6
CVSS
MEDIUM
CVE-2025-53860
pub. 2025-10-15
5.6
CVSS
MEDIUM
CVE-2024-28799
pub. 2024-08-14
5.5
CVSS
MEDIUM
CVE-2026-80158
pub. 2026-08-26
5.5
CVSS
MEDIUM
CVE-2026-65088
pub. 2026-08-25
5.5
CVSS
MEDIUM
CVE-2026-9494
pub. 2026-07-16
Showing 20 of 30 vulnerabilities