Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,189 CVEs tagged with CWE-53256 Critical, 264 High, 722 Medium, 147 Low, 0 Unrated.

CVE-2025-27496

Published Mar 13, 2025

Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3…

CVSS 3.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-2002

Published Mar 12, 2025

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP server credentials when the FTP server is deployed, and the…

CVSS 4.0 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-0071

Published Mar 11, 2025

SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-1296

Published Mar 10, 2025

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, i…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1696

Published Mar 6, 2025

A vulnerability exists in Docker Desktop prior to version 4.39.0 that could lead to the unintentional disclosure of sensitive information via application logs. In affected version…

CVSS 5.2 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-1979

Published Mar 6, 2025

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If t…

CVSS 5.7 · Medium
evidence mentions
4
Buzz score
22.6

CVE-2024-13818

Published Feb 21, 2025

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Se…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-1075

Published Feb 19, 2025

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error…

CVSS 5.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1053

Published Feb 14, 2025

Under certain error conditions at time of SANnav installation or upgrade, the encryption key can be written into and obtained from a Brocade SANnav supportsave. An attacker with…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-35202

Published Feb 11, 2025

A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to gain access to the private keys used for signing SAML Auth…

CVSS 5.1 · Medium

CVE-2024-13416

Published Feb 6, 2025

Using API in the 2N OS device, authorized user can enable logging, which discloses valid authentication tokens in system log. 2N has released an updated version 2.46 of 2N OS,…

CVSS 4.3 · Medium

CVE-2024-57957

Published Feb 6, 2025

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-23413

Published Feb 5, 2025

When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versio…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24556

Published Feb 3, 2025

Insertion of Sensitive Information into Log File vulnerability in DualCube MooWoodle moowoodle allows Retrieve Embedded Sensitive Data.This issue affects MooWoodle: from n/a throu…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-23374

Published Jan 30, 2025

Dell Networking Switches running Enterprise SONiC OS, version(s) prior to 4.4.1 and 4.2.3, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A high pri…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24884

Published Jan 29, 2025

kube-audit-rest is a simple logger of mutation/creation requests to the k8s api. If the "full-elastic-stack" example vector configuration was used for a real cluster, the previous…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2024-48852

Published Jan 29, 2025

Insertion of Sensitive Information into Log File vulnerability observed in FLEXON. Some information may be improperly disclosed through https access. This issue affects FLXEON…

CVSS 6.9 · Medium

CVE-2025-0736

Published Jan 28, 2025

A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details…

CVSS 5.5 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2025-24169

Published Jan 27, 2025

A logging issue was addressed with improved data redaction. This issue is fixed in Safari 18.3, macOS Sequoia 15.3. A malicious app may be able to bypass browser extension authent…

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-24145

Published Jan 27, 2025

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. An app may be able to view…

CVSS 3.3 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2024-54519

Published Jan 27, 2025

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24389

Published Jan 27, 2025

Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log mechanism and mails send to the system administrator. Thi…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2023-38271

Published Jan 25, 2025

IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7, and 2.3.3.7 iFix1 could allow an authenticated user to obta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 1,189 CVEsPage 13 of 48