CWE-532 · 1,116 records
Insertion of Sensitive Information into Log File
CVEs in this class
1,117 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2020-35234Weaponized | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.wp-ecommerce · easy wp smtp · CWE-532 | High7.5 | — | 64.6% | Dec 13, 2020 |
49Plan | CVE-2025-24984Weaponized | Windows NTFS Information Disclosure Vulnerabilitymicrosoft · windows 10 1507 · CWE-532 | Medium4.6 | KEV | 2.0% | Mar 11, 2025 |
48Plan | CVE-2023-43261Proof of concept | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router componentsmilesight · ur5x firmware · CWE-532 | High7.5 | — | 59.6% | Oct 4, 2023 |
48Plan | CVE-2023-21492Weaponized | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.samsung · android · CWE-532 | Medium4.4 | KEV | 2.6% | May 4, 2023 |
46Plan | CVE-2024-20440Proof of concept | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.cisco · smart license utility · CWE-532 | High7.5 | — | 51.9% | Sep 4, 2024 |
43Plan | CVE-2018-11716No exploit | An issue was discovered in Zoho ManageEngine Desktop Central before 100230.zohocorp · manageengine desktop central · CWE-532 | Critical9.8 | — | 14.3% | Jul 16, 2018 |
42Plan | CVE-2026-22778Weaponized | vLLM leaks a heap address when PIL throws an errorvllm · vllm · CWE-532 | Critical9.8 | — | 10.5% | Feb 2, 2026 |
42Plan | CVE-2018-11717No exploit | An issue was discovered in Zoho ManageEngine Desktop Central before 100251.zohocorp · manageengine desktop central · CWE-532 | Critical9.8 | — | 8.6% | Jul 16, 2018 |
40Plan | CVE-2017-7550No exploit | A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.redhat · ansible · CWE-532 | Critical9.8 | — | 3.6% | Nov 21, 2017 |
40Plan | CVE-2019-3888No exploit | A vulnerability was found in Undertow web server before 2.0.21.redhat · undertow · CWE-532 | Critical9.8 | — | 3.0% | Jun 12, 2019 |
40Plan | CVE-2018-1000060No exploit | Sensu, Inc.sensu · sensu core · CWE-532 | Critical9.8 | — | 2.4% | Feb 9, 2018 |
40Plan | CVE-2021-32724Proof of concept | check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attackcheck-spelling · check-spelling · CWE-532 | Critical9.9 | — | 2.3% | Sep 9, 2021 |
40Plan | CVE-2017-7214No exploit | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.openstack · nova · CWE-532 | Critical9.8 | — | 2.3% | Mar 21, 2017 |
40Plan | CVE-2019-4008No exploit | API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.ibm · api connect · CWE-532 | Critical9.8 | — | 2.3% | Feb 7, 2019 |
40Plan | CVE-2018-16049No exploit | An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.gitlab · gitlab · CWE-532 | Critical9.8 | — | 2.1% | Oct 3, 2018 |
40Plan | CVE-2017-8074No exploit | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadectp-link · tl-sg108e firmware · CWE-532 | Critical9.8 | — | 1.9% | Apr 23, 2017 |
40Plan | CVE-2017-6165No exploit | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1f5 · big-ip access policy manager · CWE-532 | Critical9.8 | — | 1.9% | Oct 20, 2017 |
40Plan | CVE-2019-10212No exploit | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.redhat · undertow · CWE-532 | Critical9.8 | — | 1.9% | Oct 2, 2019 |
40Plan | CVE-2018-1264No exploit | Log Cache logs UAA client secret on startuppivotal software · cloud foundry log cache · CWE-532 | Critical9.8 | — | 1.8% | Oct 5, 2018 |
40Plan | CVE-2017-8075No exploit | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.tp-link · tl-sg108e firmware · CWE-532 | Critical9.8 | — | 1.8% | Apr 23, 2017 |
40Plan | CVE-2026-49200No exploit | Acer Wave 7 router: Broken Access Controlacer · wave 7 firmware · CWE-532 | Critical10.0 | — | 0.6% | May 29, 2026 |
39Monitor | CVE-2018-1000123No exploit | Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throuionicframework · ios keychain · CWE-532 | Critical9.8 | — | 1.4% | Mar 13, 2018 |
39Monitor | CVE-2017-4955No exploit | An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior pivotal software · cloud foundry elastic runtime · CWE-532 | Critical9.8 | — | 1.4% | Jun 13, 2017 |
39Monitor | CVE-2017-15366No exploit | Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.ndocsoftware · ndoc · CWE-532 | Critical9.8 | — | 1.4% | Oct 26, 2017 |
39Monitor | CVE-2018-1117No exploit | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Manaovirt · ovirt-ansible-roles · CWE-532 | Critical9.8 | — | 1.4% | Jun 19, 2018 |
- CVE-2020-3523449Plan
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.
HighCVSS 7.5WeaponizedEPSS 65%wp-ecommerce · easy wp smtpDec 13, 2020
- CVE-2025-2498449Plan
Windows NTFS Information Disclosure Vulnerability
MediumCVSS 4.6KEVWeaponizedEPSS 2%microsoft · windows 10 1507Mar 11, 2025
- CVE-2023-4326148Plan
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components
HighCVSS 7.5Proof of conceptEPSS 60%milesight · ur5x firmwareOct 4, 2023
- CVE-2023-2149248Plan
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
MediumCVSS 4.4KEVWeaponizedEPSS 3%samsung · androidMay 4, 2023
- CVE-2024-2044046Plan
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.
HighCVSS 7.5Proof of conceptEPSS 52%cisco · smart license utilitySep 4, 2024
- CVE-2018-1171643Plan
An issue was discovered in Zoho ManageEngine Desktop Central before 100230.
CriticalCVSS 9.8No exploitEPSS 14%zohocorp · manageengine desktop centralJul 16, 2018
- CVE-2026-2277842Plan
vLLM leaks a heap address when PIL throws an error
CriticalCVSS 9.8WeaponizedEPSS 10%vllm · vllmFeb 2, 2026
- CVE-2018-1171742Plan
An issue was discovered in Zoho ManageEngine Desktop Central before 100251.
CriticalCVSS 9.8No exploitEPSS 9%zohocorp · manageengine desktop centralJul 16, 2018
- CVE-2017-755040Plan
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.
CriticalCVSS 9.8No exploitEPSS 4%redhat · ansibleNov 21, 2017
- CVE-2019-388840Plan
A vulnerability was found in Undertow web server before 2.0.21.
CriticalCVSS 9.8No exploitEPSS 3%redhat · undertowJun 12, 2019
- CVE-2018-100006040Plan
Sensu, Inc.
CriticalCVSS 9.8No exploitEPSS 2%sensu · sensu coreFeb 9, 2018
- CVE-2021-3272440Plan
check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attack
CriticalCVSS 9.9Proof of conceptEPSS 2%check-spelling · check-spellingSep 9, 2021
- CVE-2017-721440Plan
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
CriticalCVSS 9.8No exploitEPSS 2%openstack · novaMar 21, 2017
- CVE-2019-400840Plan
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.
CriticalCVSS 9.8No exploitEPSS 2%ibm · api connectFeb 7, 2019
- CVE-2018-1604940Plan
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.
CriticalCVSS 9.8No exploitEPSS 2%gitlab · gitlabOct 3, 2018
- CVE-2017-807440Plan
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadec
CriticalCVSS 9.8No exploitEPSS 2%tp-link · tl-sg108e firmwareApr 23, 2017
- CVE-2017-616540Plan
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1
CriticalCVSS 9.8No exploitEPSS 2%f5 · big-ip access policy managerOct 20, 2017
- CVE-2019-1021240Plan
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.
CriticalCVSS 9.8No exploitEPSS 2%redhat · undertowOct 2, 2019
- CVE-2018-126440Plan
Log Cache logs UAA client secret on startup
CriticalCVSS 9.8No exploitEPSS 2%pivotal software · cloud foundry log cacheOct 5, 2018
- CVE-2017-807540Plan
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.
CriticalCVSS 9.8No exploitEPSS 2%tp-link · tl-sg108e firmwareApr 23, 2017
- CVE-2026-4920040Plan
Acer Wave 7 router: Broken Access Control
CriticalCVSS 10.0No exploitEPSS 1%acer · wave 7 firmwareMay 29, 2026
- CVE-2018-100012339Monitor
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throu
CriticalCVSS 9.8No exploitEPSS 1%ionicframework · ios keychainMar 13, 2018
- CVE-2017-495539Monitor
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior
CriticalCVSS 9.8No exploitEPSS 1%pivotal software · cloud foundry elastic runtimeJun 13, 2017
- CVE-2017-1536639Monitor
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.
CriticalCVSS 9.8No exploitEPSS 1%ndocsoftware · ndocOct 26, 2017
- CVE-2018-111739Monitor
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Mana
CriticalCVSS 9.8No exploitEPSS 1%ovirt · ovirt-ansible-rolesJun 19, 2018