Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-53256 Critical, 264 High, 721 Medium, 147 Low, 0 Unrated.

CVE-2026-75057

Published Aug 17, 2026

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

CVSS 6.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59911

Published Aug 17, 2026

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local ac…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-74870

Published Aug 17, 2026

openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print t…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-19483

Published Aug 13, 2026

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-19502

Published Aug 12, 2026

MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were writ…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-18097

Published Aug 12, 2026

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-68969

Published Aug 12, 2026

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` a…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-47234

Published Aug 12, 2026

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` l…

CVSS 4.4 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-18710

Published Aug 11, 2026

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext d…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-71845

Published Aug 11, 2026

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconne…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-71474

Published Aug 11, 2026

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A…

CVSS 6.3 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-20708

Published Aug 11, 2026

Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary w…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-65945

Published Aug 10, 2026

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-19363

Published Aug 9, 2026

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation…

CVSS 5.5 · Medium
evidence mentions
4
Buzz score
21.1

CVE-2026-46358

Published Aug 7, 2026

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting i…

CVSS 5.4 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-0637

Published Aug 6, 2026

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or s…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-21766

Published Aug 5, 2026

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific use cases and specific configu…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-20289

Published Aug 5, 2026

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is…

CVSS 5.7 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-65311

Published Jul 31, 2026

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's logging level and target witho…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-12947

Published Jul 30, 2026

IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44105

Published Jul 30, 2026

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-59326

Published Jul 30, 2026

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP cli…

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-14528

Published Jul 28, 2026

IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-64800

Published Jul 23, 2026

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 1,188 CVEsPage 1 of 48