Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,180 CVEs tagged with CWE-53256 Critical, 262 High, 715 Medium, 147 Low, 0 Unrated.

CVE-2025-32016

Published Apr 9, 2025

Microsoft Identity Web is a library which contains a set of reusable classes used in conjunction with ASP.NET Core for integrating with the Microsoft identity platform (formerly A…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-27391

Published Apr 9, 2025

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-30677

Published Apr 9, 2025

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-25013

Published Apr 8, 2025

Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-25002

Published Apr 8, 2025

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-32054

Published Apr 3, 2025

In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file

CVSS 3.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31479

Published Apr 2, 2025

canonical/get-workflow-version-action is a GitHub composite action to get commit SHA that GitHub Actions reusable workflow was called with. Prior to 1.0.1, if the get-workflow-ver…

CVSS 8.2 · High
evidence mentions
3
Buzz score
18.9

CVE-2025-31788

Published Apr 1, 2025

Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerato…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-1998

Published Mar 27, 2025

IBM UrbanCode Deploy (UCD) through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.0 / IBM DevOps Deploy 8.0 through 8.0.1.4 and 8.1 through 8.1 stores potentially sensiti…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31139

Published Mar 27, 2025

In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-20231

Published Mar 26, 2025

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privilege…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-30205

Published Mar 24, 2025

kanidim-provision is a helper utility that uses kanidm's API to provision users, groups and oauth2 systems. Prior to version 1.2.0, a faulty function intrumentation in the (option…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-0495

Published Mar 17, 2025

Buildx is a Docker CLI plugin that extends build capabilities using BuildKit. Cache backends support credentials by setting secrets directly as attribute values in cache-to/cache…

CVSS 4.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-27496

Published Mar 13, 2025

Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-2002

Published Mar 12, 2025

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-0071

Published Mar 11, 2025

SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-1296

Published Mar 10, 2025

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, i…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1696

Published Mar 6, 2025

A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected version…

CVSS 5.2 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-1979

Published Mar 6, 2025

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If t…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2024-13818

Published Feb 21, 2025

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Se…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,180 CVEsPage 12 of 48