CWE-532 · 1 116 записей
Insertion of Sensitive Information into Log File
CVE этого класса
1 117 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2020-35234Готовый эксплойт | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.wp-ecommerce · easy wp smtp · CWE-532 | Высокая7,5 | — | 64,6 % | 13 дек. 2020 г. |
49В плане | CVE-2025-24984Готовый эксплойт | Windows NTFS Information Disclosure Vulnerabilitymicrosoft · windows 10 1507 · CWE-532 | Средняя4,6 | KEV | 2,0 % | 11 мар. 2025 г. |
48В плане | CVE-2023-43261Proof of concept | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router componentsmilesight · ur5x firmware · CWE-532 | Высокая7,5 | — | 59,6 % | 4 окт. 2023 г. |
48В плане | CVE-2023-21492Готовый эксплойт | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.samsung · android · CWE-532 | Средняя4,4 | KEV | 2,6 % | 4 мая 2023 г. |
46В плане | CVE-2024-20440Proof of concept | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.cisco · smart license utility · CWE-532 | Высокая7,5 | — | 51,9 % | 4 сент. 2024 г. |
43В плане | CVE-2018-11716Эксплойта нет | An issue was discovered in Zoho ManageEngine Desktop Central before 100230.zohocorp · manageengine desktop central · CWE-532 | Критическая9,8 | — | 14,3 % | 16 июл. 2018 г. |
42В плане | CVE-2026-22778Готовый эксплойт | vLLM leaks a heap address when PIL throws an errorvllm · vllm · CWE-532 | Критическая9,8 | — | 10,5 % | 2 февр. 2026 г. |
42В плане | CVE-2018-11717Эксплойта нет | An issue was discovered in Zoho ManageEngine Desktop Central before 100251.zohocorp · manageengine desktop central · CWE-532 | Критическая9,8 | — | 8,6 % | 16 июл. 2018 г. |
40В плане | CVE-2017-7550Эксплойта нет | A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.redhat · ansible · CWE-532 | Критическая9,8 | — | 3,6 % | 21 нояб. 2017 г. |
40В плане | CVE-2019-3888Эксплойта нет | A vulnerability was found in Undertow web server before 2.0.21.redhat · undertow · CWE-532 | Критическая9,8 | — | 3,0 % | 12 июн. 2019 г. |
40В плане | CVE-2018-1000060Эксплойта нет | Sensu, Inc.sensu · sensu core · CWE-532 | Критическая9,8 | — | 2,4 % | 9 февр. 2018 г. |
40В плане | CVE-2021-32724Proof of concept | check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attackcheck-spelling · check-spelling · CWE-532 | Критическая9,9 | — | 2,3 % | 9 сент. 2021 г. |
40В плане | CVE-2017-7214Эксплойта нет | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.openstack · nova · CWE-532 | Критическая9,8 | — | 2,3 % | 21 мар. 2017 г. |
40В плане | CVE-2019-4008Эксплойта нет | API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.ibm · api connect · CWE-532 | Критическая9,8 | — | 2,3 % | 7 февр. 2019 г. |
40В плане | CVE-2018-16049Эксплойта нет | An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.gitlab · gitlab · CWE-532 | Критическая9,8 | — | 2,1 % | 3 окт. 2018 г. |
40В плане | CVE-2017-8074Эксплойта нет | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadectp-link · tl-sg108e firmware · CWE-532 | Критическая9,8 | — | 1,9 % | 23 апр. 2017 г. |
40В плане | CVE-2017-6165Эксплойта нет | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1f5 · big-ip access policy manager · CWE-532 | Критическая9,8 | — | 1,9 % | 20 окт. 2017 г. |
40В плане | CVE-2019-10212Эксплойта нет | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.redhat · undertow · CWE-532 | Критическая9,8 | — | 1,9 % | 2 окт. 2019 г. |
40В плане | CVE-2018-1264Эксплойта нет | Log Cache logs UAA client secret on startuppivotal software · cloud foundry log cache · CWE-532 | Критическая9,8 | — | 1,8 % | 5 окт. 2018 г. |
40В плане | CVE-2017-8075Эксплойта нет | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.tp-link · tl-sg108e firmware · CWE-532 | Критическая9,8 | — | 1,8 % | 23 апр. 2017 г. |
40В плане | CVE-2026-49200Эксплойта нет | Acer Wave 7 router: Broken Access Controlacer · wave 7 firmware · CWE-532 | Критическая10,0 | — | 0,6 % | 29 мая 2026 г. |
39Наблюдать | CVE-2018-1000123Эксплойта нет | Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throuionicframework · ios keychain · CWE-532 | Критическая9,8 | — | 1,4 % | 13 мар. 2018 г. |
39Наблюдать | CVE-2017-4955Эксплойта нет | An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior pivotal software · cloud foundry elastic runtime · CWE-532 | Критическая9,8 | — | 1,4 % | 13 июн. 2017 г. |
39Наблюдать | CVE-2017-15366Эксплойта нет | Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.ndocsoftware · ndoc · CWE-532 | Критическая9,8 | — | 1,4 % | 26 окт. 2017 г. |
39Наблюдать | CVE-2018-1117Эксплойта нет | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Manaovirt · ovirt-ansible-roles · CWE-532 | Критическая9,8 | — | 1,4 % | 19 июн. 2018 г. |
- CVE-2020-3523449В плане
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 65 %wp-ecommerce · easy wp smtp13 дек. 2020 г.
- CVE-2025-2498449В плане
Windows NTFS Information Disclosure Vulnerability
СредняяCVSS 4,6KEVГотовый эксплойтEPSS 2 %microsoft · windows 10 150711 мар. 2025 г.
- CVE-2023-4326148В плане
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components
ВысокаяCVSS 7,5Proof of conceptEPSS 60 %milesight · ur5x firmware4 окт. 2023 г.
- CVE-2023-2149248В плане
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
СредняяCVSS 4,4KEVГотовый эксплойтEPSS 3 %samsung · android4 мая 2023 г.
- CVE-2024-2044046В плане
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.
ВысокаяCVSS 7,5Proof of conceptEPSS 52 %cisco · smart license utility4 сент. 2024 г.
- CVE-2018-1171643В плане
An issue was discovered in Zoho ManageEngine Desktop Central before 100230.
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %zohocorp · manageengine desktop central16 июл. 2018 г.
- CVE-2026-2277842В плане
vLLM leaks a heap address when PIL throws an error
КритическаяCVSS 9,8Готовый эксплойтEPSS 10 %vllm · vllm2 февр. 2026 г.
- CVE-2018-1171742В плане
An issue was discovered in Zoho ManageEngine Desktop Central before 100251.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %zohocorp · manageengine desktop central16 июл. 2018 г.
- CVE-2017-755040В плане
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %redhat · ansible21 нояб. 2017 г.
- CVE-2019-388840В плане
A vulnerability was found in Undertow web server before 2.0.21.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %redhat · undertow12 июн. 2019 г.
- CVE-2018-100006040В плане
Sensu, Inc.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sensu · sensu core9 февр. 2018 г.
- CVE-2021-3272440В плане
check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attack
КритическаяCVSS 9,9Proof of conceptEPSS 2 %check-spelling · check-spelling9 сент. 2021 г.
- CVE-2017-721440В плане
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openstack · nova21 мар. 2017 г.
- CVE-2019-400840В плане
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %ibm · api connect7 февр. 2019 г.
- CVE-2018-1604940В плане
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gitlab · gitlab3 окт. 2018 г.
- CVE-2017-807440В плане
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadec
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tp-link · tl-sg108e firmware23 апр. 2017 г.
- CVE-2017-616540В плане
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %f5 · big-ip access policy manager20 окт. 2017 г.
- CVE-2019-1021240В плане
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %redhat · undertow2 окт. 2019 г.
- CVE-2018-126440В плане
Log Cache logs UAA client secret on startup
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pivotal software · cloud foundry log cache5 окт. 2018 г.
- CVE-2017-807540В плане
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tp-link · tl-sg108e firmware23 апр. 2017 г.
- CVE-2026-4920040В плане
Acer Wave 7 router: Broken Access Control
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %acer · wave 7 firmware29 мая 2026 г.
- CVE-2018-100012339Наблюдать
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throu
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ionicframework · ios keychain13 мар. 2018 г.
- CVE-2017-495539Наблюдать
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pivotal software · cloud foundry elastic runtime13 июн. 2017 г.
- CVE-2017-1536639Наблюдать
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ndocsoftware · ndoc26 окт. 2017 г.
- CVE-2018-111739Наблюдать
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Mana
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ovirt · ovirt-ansible-roles19 июн. 2018 г.