Skip to content
Noroxi

CWE-532 · 1,116 records

Insertion of Sensitive Information into Log File

CVEs in this class

1,117 records

  • The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.

    HighCVSS 7.5WeaponizedEPSS 65%

    wp-ecommerce · easy wp smtpDec 13, 2020

  • Windows NTFS Information Disclosure Vulnerability

    MediumCVSS 4.6KEVWeaponizedEPSS 2%

    microsoft · windows 10 1507Mar 11, 2025

  • An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components

    HighCVSS 7.5Proof of conceptEPSS 60%

    milesight · ur5x firmwareOct 4, 2023

  • Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

    MediumCVSS 4.4KEVWeaponizedEPSS 3%

    samsung · androidMay 4, 2023

  • A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.

    HighCVSS 7.5Proof of conceptEPSS 52%

    cisco · smart license utilitySep 4, 2024

  • An issue was discovered in Zoho ManageEngine Desktop Central before 100230.

    CriticalCVSS 9.8No exploitEPSS 14%

    zohocorp · manageengine desktop centralJul 16, 2018

  • vLLM leaks a heap address when PIL throws an error

    CriticalCVSS 9.8WeaponizedEPSS 10%

    vllm · vllmFeb 2, 2026

  • An issue was discovered in Zoho ManageEngine Desktop Central before 100251.

    CriticalCVSS 9.8No exploitEPSS 9%

    zohocorp · manageengine desktop centralJul 16, 2018

  • A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.

    CriticalCVSS 9.8No exploitEPSS 4%

    redhat · ansibleNov 21, 2017

  • A vulnerability was found in Undertow web server before 2.0.21.

    CriticalCVSS 9.8No exploitEPSS 3%

    redhat · undertowJun 12, 2019

  • Sensu, Inc.

    CriticalCVSS 9.8No exploitEPSS 2%

    sensu · sensu coreFeb 9, 2018

  • check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attack

    CriticalCVSS 9.9Proof of conceptEPSS 2%

    check-spelling · check-spellingSep 9, 2021

  • An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    openstack · novaMar 21, 2017

  • API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.

    CriticalCVSS 9.8No exploitEPSS 2%

    ibm · api connectFeb 7, 2019

  • An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.

    CriticalCVSS 9.8No exploitEPSS 2%

    gitlab · gitlabOct 3, 2018

  • On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadec

    CriticalCVSS 9.8No exploitEPSS 2%

    tp-link · tl-sg108e firmwareApr 23, 2017

  • In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1

    CriticalCVSS 9.8No exploitEPSS 2%

    f5 · big-ip access policy managerOct 20, 2017

  • A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.

    CriticalCVSS 9.8No exploitEPSS 2%

    redhat · undertowOct 2, 2019

  • Log Cache logs UAA client secret on startup

    CriticalCVSS 9.8No exploitEPSS 2%

    pivotal software · cloud foundry log cacheOct 5, 2018

  • On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.

    CriticalCVSS 9.8No exploitEPSS 2%

    tp-link · tl-sg108e firmwareApr 23, 2017

  • Acer Wave 7 router: Broken Access Control

    CriticalCVSS 10.0No exploitEPSS 1%

    acer · wave 7 firmwareMay 29, 2026

  • Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throu

    CriticalCVSS 9.8No exploitEPSS 1%

    ionicframework · ios keychainMar 13, 2018

  • CVE-2017-4955
    39Monitor

    An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior

    CriticalCVSS 9.8No exploitEPSS 1%

    pivotal software · cloud foundry elastic runtimeJun 13, 2017

  • Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.

    CriticalCVSS 9.8No exploitEPSS 1%

    ndocsoftware · ndocOct 26, 2017

  • CVE-2018-1117
    39Monitor

    ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Mana

    CriticalCVSS 9.8No exploitEPSS 1%

    ovirt · ovirt-ansible-rolesJun 19, 2018

All vulnerability classes