Skip to main content

CWE archive

CWE-779 CVEs

Programmatic archive

20 CVEs tagged with CWE-7791 Critical, 5 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2026-20210

Published May 14, 2026

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configu…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2026-20209

Published May 14, 2026

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2025-69230

Published Jan 6, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8696

Published Sep 10, 2025

If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for the system running the Stork server. This issue affects Stor…

CVSS 7.5 · High

CVE-2025-51397

Published Jul 21, 2025

A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53636

Published Jul 11, 2025

Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many errors. Users who flood logs can create very large log files…

CVSS 5.4 · Medium

CVE-2024-55628

Published Jan 6, 2025

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lea…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36072

Published Jun 27, 2024

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector a…

CVSS 9.8 · Critical

CVE-2024-36416

Published Jun 10, 2024

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1141

Published Feb 1, 2024

A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39874

Published Oct 7, 2022

Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31004

Published Jun 2, 2022

CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25779

Published May 4, 2022

Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries in audit log. This issue affects: Secomea GateManager versi…

CVSS 4.3 · Medium

CVE-2022-22291

Published Feb 11, 2022

Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25423

Published Jun 11, 2021

Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi password connected to the user sm…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25422

Published Jun 11, 2021

Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user sma…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25421

Published Jun 11, 2021

Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user sm…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25420

Published Jun 11, 2021

Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user sma…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1