Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,164 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 146 Low, 0 Unrated.

CVE-2019-20625

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-20…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-16528

Published Mar 20, 2020

An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive information, such as deleted/suppress…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5262

Published Mar 19, 2020

In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--fro,-pr`, etc.) is shown in pl…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18576

Published Mar 13, 2020

Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Malicious local users with access…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19756

Published Mar 13, 2020

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of managed systems, being written to a…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16157

Published Mar 13, 2020

An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug comm…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4083

Published Mar 5, 2020

HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0018

Published Feb 13, 2020

In MotionEntry::appendDescription of InputDispatcher.cpp, there is a possible log information disclosure. This could lead to local disclosure of user input with System execution p…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-1942

Published Feb 11, 2020

In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the event a node attempted to join…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16204

Published Feb 5, 2020

Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used between the switch and an exter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16203

Published Feb 5, 2020

Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a command line option when configu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18193

Published Feb 3, 2020

In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3.4.109, 4.0.027.13, 4.0.125 an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1928

Published Jan 28, 2020

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purposes. This would expose literal v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5225

Published Jan 24, 2020

Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the system administrator, did not pro…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7215

Published Jan 20, 2020

An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External system configuration data (used…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18244

Published Jan 15, 2020

In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when service accounts are customized during installation or upg…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11292

Published Jan 9, 2020

Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3429

Published Dec 23, 2019

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information without authorization, causing…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19150

Published Dec 23, 2019

On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 926-950 of 1,164 CVEsPage 38 of 47