Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,164 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 146 Low, 0 Unrated.

CVE-2020-4477

Published Jun 15, 2020

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in further attacks against the syste…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12023

Published Jun 11, 2020

Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). U…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-13223

Published Jun 10, 2020

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13830

Published Jun 4, 2020

An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11094

Published Jun 4, 2020

The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) when…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3281

Published Jun 3, 2020

A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in cl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7654

Published May 29, 2020

All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2004

Published May 13, 2020

Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also k…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11932

Published May 13, 2020

It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-1698

Published May 11, 2020

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerabil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4286

Published Apr 29, 2020

IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 could disclose highly senstiive user information to an authenticated user with physical access to the device. IBM X-Forc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10712

Published Apr 22, 2020

A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to ga…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-6224

Published Apr 14, 2020

SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access user sensitive data such as pas…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1624

Published Apr 8, 2020

A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This issue affects all versions of Ju…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1623

Published Apr 8, 2020

A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all versions of Junos OS Evolved prior to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1622

Published Apr 8, 2020

A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affects all versions of Junos OS Ev…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1621

Published Apr 8, 2020

A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos OS Evolved prior to 19.3R1.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1620

Published Apr 8, 2020

A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of Junos OS Evolved prior to 19.3R…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-1987

Published Apr 8, 2020

An information exposure vulnerability in the logging component of Palo Alto Networks Global Protect Agent allows a local authenticated user to read VPN cookie information when the…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11605

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7599

Published Mar 30, 2020

All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while ru…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 901-925 of 1,164 CVEsPage 37 of 47