Skip to main content

CWE archive

CWE-117 CVEs

Programmatic archive

102 CVEs tagged with CWE-1175 Critical, 15 High, 75 Medium, 7 Low, 0 Unrated.

CVE-2026-62948

Published Jul 15, 2026

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefi…

CVSS 9.6 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-12616

Published Jun 29, 2026

The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that string into three log statements be…

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-10745

Published Jun 24, 2026

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging. This issue affect…

CVSS 7.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-20260

Published Jun 10, 2026

In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escap…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45565

Published Jun 10, 2026

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, EscapedString (app/modules/roxywi/class_models.py:16-30) is t…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-9016

Published Jun 6, 2026

The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and including,…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
32.3

CVE-2026-5078

Published Jun 3, 2026

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutraliz…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-45679

Published Jun 2, 2026

OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status m…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-6494

Published Apr 17, 2026

A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` param…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-34478

Published Apr 10, 2026

Apache Log4j Core's Rfc5424Layout https://logging.apache.org/log4j/2.x/manual/layouts.html#RFC5424Layout , in versions 2.21.0 through 2.25.3, is vulnerable to log injection via C…

CVSS 6.9 · Medium
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-14684

Published Mar 25, 2026

IBM Maximo Application Suite - Monitor Component 9.1, 9.0, 8.11, and 8.10 could allow an unauthorized user to inject data into log messages due to improper neutralization of speci…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-24308

Published Mar 7, 2026

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client conf…

CVSS 7.5 · High
evidence mentions
10
Buzz score
38.5
Vendor/product tagsBeta · best-effort

CVE-2025-59784

Published Mar 4, 2026

2N Access Commander version 3.4.1 and prior is vulnerable to log pollution. Certain parameters sent over API may be included in the logs without prior validation or sanitisation.…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-25548

Published Feb 18, 2026

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. A critical Remote Code Execution (RCE) vulnerability exists in InvoicePlane 1.7…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-12755

Published Feb 17, 2026

IBM MQ Operator (SC2 v3.2.0–3.8.1, LTS v2.0.0–2.0.29) and IBM‑supplied MQ Advanced container images (across affected SC2, CD, and LTS 9.3.x–9.4.x releases) contain a vulnerability…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-11537

Published Feb 10, 2026

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Autho…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-1337

Published Feb 6, 2026

Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that trea…

CVSS 1.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66577

Published Dec 5, 2025

cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allows attacker-controlled HTTP headers to influence server-visi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20384

Published Dec 3, 2025

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.6, and 9.3.2411.117.125, an unauthenticated a…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-36159

Published Nov 20, 2025

IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their identity due to improper neutralization of output.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11627

Published Oct 30, 2025

The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log file poisoning in all versions up to, and including, 1.47.…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2025-57564

Published Oct 7, 2025

CubeAPM nightly-2025-08-01-1 allow unauthenticated attackers to inject arbitrary log entries into production systems via the /api/logs/insert/elasticsearch/_bulk endpoint. This en…

CVSS 8.2 · High

CVE-2025-58580

Published Oct 6, 2025

An API endpoint allows arbitrary log entries to be created via POST request. Without sufficient validation of the input data, an attacker can create manipulated log…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10217

Published Sep 30, 2025

A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log data or to inject crafted data in logfile for potentially carr…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 102 CVEsPage 1 of 5