Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,174 CVEs tagged with CWE-53256 Critical, 261 High, 710 Medium, 147 Low, 0 Unrated.

CVE-2020-10762

Published Nov 24, 2020

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4671

Published Nov 16, 2020

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.2 and 5.2.0.0 through 5.2.6.5 stores potentially sensitive information in log files that could be read by an aut…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2048

Published Nov 12, 2020

An information exposure through log file vulnerability exists where the password for the configured system proxy server for a PAN-OS appliance may be displayed in cleartext when u…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11646

Published Oct 15, 2020

A log information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view log…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-11643

Published Oct 15, 2020

An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view inform…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2020-26605

Published Oct 6, 2020

An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software. They allow attackers to obtain sensitive information by reading a log. The S…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25987

Published Oct 6, 2020

MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog. Hash type is bcrypt and hashcat mode 3200 can be used to crack the hash.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9486

Published Oct 1, 2020

In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was triggered, the flow definition c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15370

Published Sep 25, 2020

Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext. The vulnerability is due to incorre…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14330

Published Sep 11, 2020

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output. This flaw allows an att…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2044

Published Sep 9, 2020

An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-2043

Published Sep 9, 2020

An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-24566

Published Sep 9, 2020

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's exe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7322

Published Sep 9, 2020

Information Disclosure Vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to gain access to sensitive information…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25046

Published Aug 31, 2020

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The USB driver leaks address information via kernel logging. The Samsung IDs are SVE-2…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14518

Published Aug 21, 2020

Philips DreamMapper, Version 2.24 and prior. Information written to log files can give guidance to a potential attacker.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6653

Published Aug 12, 2020

Eaton's Secure connect mobile app v1.7.3 & prior stores the user login credentials in logcat file when user create or register the account on the Mobile app. A malicious app or un…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-6295

Published Aug 12, 2020

Under certain conditions the SAP Adaptive Server Enterprise, version 16.0, allows an attacker to access encrypted sensitive and confidential information through publicly readable…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-15829

Published Aug 8, 2020

In JetBrains TeamCity before 2019.2.3, password parameters could be disclosed via build logs.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 876-900 of 1,174 CVEsPage 36 of 47