Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,163 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 145 Low, 0 Unrated.

CVE-2025-36599

Published Jul 9, 2025

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access coul…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5464

Published Jul 8, 2025

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6711

Published Jul 7, 2025

An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when certain error conditions are encountered. This issue affects M…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49846

Published Jul 3, 2025

wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the i…

CVSS 4.1 · Medium

CVE-2025-6587

Published Jul 3, 2025

System environment variables are recorded in Docker Desktop diagnostic logs, when using shell auto-completion. This leads to unintentional disclosure of sensitive information such…

CVSS 5.2 · Medium

CVE-2025-6624

Published Jun 26, 2025

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials p…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52893

Published Jun 25, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. OpenBao before v2.3.0 may leak sensitive i…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7586

Published Jun 20, 2025

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where w…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50200

Published Jun 19, 2025

RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying RabbitMQ api wi…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2327

Published Jun 16, 2025

A flaw exists in FlashArray whereby the Key Encryption Key (KEK) is logged during key rotation when RDL is configured.

CVSS 5.1 · Medium

CVE-2025-49009

Published Jun 5, 2025

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results i…

CVSS 6.2 · Medium

CVE-2025-48493

Published Jun 5, 2025

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, the extension writes commands sequence to logs. Prior to ver…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48955

Published Jun 2, 2025

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in…

CVSS 6.2 · Medium

CVE-2025-46777

Published May 28, 2025

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticate…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-48374

Published May 22, 2025

zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. Prior to version 2.1.3 (corresponding to pseudoversion 1.4.4-0.202505…

CVSS 5.5 · Medium

CVE-2025-26864

Published May 14, 2025

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue aff…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26795

Published May 14, 2025

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-j…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31213

Published May 12, 2025

A logging issue was addressed with improved data redaction. This issue is fixed in iPadOS 17.7.7, macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. An app may be able…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2025-3911

Published Apr 29, 2025

Recording of environment variables, configured for running containers, in Docker Desktop application logs could lead to unintentional disclosure of sensitive information such as a…

CVSS 5.2 · Medium
Showing 226-250 of 1,163 CVEsPage 10 of 47