CWE-532 · 1.116 kayıt
Insertion of Sensitive Information into Log File
Bu sınıftaki CVE’ler
1.117 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2020-35234Silahlaştırılmış | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.wp-ecommerce · easy wp smtp · CWE-532 | Yüksek7,5 | — | %64,6 | 13 Ara 2020 |
49Planlayın | CVE-2025-24984Silahlaştırılmış | Windows NTFS Information Disclosure Vulnerabilitymicrosoft · windows 10 1507 · CWE-532 | Orta4,6 | KEV | %2,0 | 11 Mar 2025 |
48Planlayın | CVE-2023-43261Kavram kanıtı | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router componentsmilesight · ur5x firmware · CWE-532 | Yüksek7,5 | — | %59,6 | 4 Eki 2023 |
48Planlayın | CVE-2023-21492Silahlaştırılmış | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.samsung · android · CWE-532 | Orta4,4 | KEV | %2,6 | 4 May 2023 |
46Planlayın | CVE-2024-20440Kavram kanıtı | A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.cisco · smart license utility · CWE-532 | Yüksek7,5 | — | %51,9 | 4 Eyl 2024 |
43Planlayın | CVE-2018-11716İstismar yok | An issue was discovered in Zoho ManageEngine Desktop Central before 100230.zohocorp · manageengine desktop central · CWE-532 | Kritik9,8 | — | %14,3 | 16 Tem 2018 |
42Planlayın | CVE-2026-22778Silahlaştırılmış | vLLM leaks a heap address when PIL throws an errorvllm · vllm · CWE-532 | Kritik9,8 | — | %10,5 | 2 Şub 2026 |
42Planlayın | CVE-2018-11717İstismar yok | An issue was discovered in Zoho ManageEngine Desktop Central before 100251.zohocorp · manageengine desktop central · CWE-532 | Kritik9,8 | — | %8,6 | 16 Tem 2018 |
40Planlayın | CVE-2017-7550İstismar yok | A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.redhat · ansible · CWE-532 | Kritik9,8 | — | %3,6 | 21 Kas 2017 |
40Planlayın | CVE-2019-3888İstismar yok | A vulnerability was found in Undertow web server before 2.0.21.redhat · undertow · CWE-532 | Kritik9,8 | — | %3,0 | 12 Haz 2019 |
40Planlayın | CVE-2018-1000060İstismar yok | Sensu, Inc.sensu · sensu core · CWE-532 | Kritik9,8 | — | %2,4 | 9 Şub 2018 |
40Planlayın | CVE-2021-32724Kavram kanıtı | check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attackcheck-spelling · check-spelling · CWE-532 | Kritik9,9 | — | %2,3 | 9 Eyl 2021 |
40Planlayın | CVE-2017-7214İstismar yok | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.openstack · nova · CWE-532 | Kritik9,8 | — | %2,3 | 21 Mar 2017 |
40Planlayın | CVE-2019-4008İstismar yok | API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.ibm · api connect · CWE-532 | Kritik9,8 | — | %2,3 | 7 Şub 2019 |
40Planlayın | CVE-2018-16049İstismar yok | An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.gitlab · gitlab · CWE-532 | Kritik9,8 | — | %2,1 | 3 Eki 2018 |
40Planlayın | CVE-2017-8074İstismar yok | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadectp-link · tl-sg108e firmware · CWE-532 | Kritik9,8 | — | %1,9 | 23 Nis 2017 |
40Planlayın | CVE-2017-6165İstismar yok | In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1f5 · big-ip access policy manager · CWE-532 | Kritik9,8 | — | %1,9 | 20 Eki 2017 |
40Planlayın | CVE-2019-10212İstismar yok | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.redhat · undertow · CWE-532 | Kritik9,8 | — | %1,9 | 2 Eki 2019 |
40Planlayın | CVE-2018-1264İstismar yok | Log Cache logs UAA client secret on startuppivotal software · cloud foundry log cache · CWE-532 | Kritik9,8 | — | %1,8 | 5 Eki 2018 |
40Planlayın | CVE-2017-8075İstismar yok | On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.tp-link · tl-sg108e firmware · CWE-532 | Kritik9,8 | — | %1,8 | 23 Nis 2017 |
40Planlayın | CVE-2026-49200İstismar yok | Acer Wave 7 router: Broken Access Controlacer · wave 7 firmware · CWE-532 | Kritik10,0 | — | %0,6 | 29 May 2026 |
39İzleyin | CVE-2018-1000123İstismar yok | Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throuionicframework · ios keychain · CWE-532 | Kritik9,8 | — | %1,4 | 13 Mar 2018 |
39İzleyin | CVE-2017-4955İstismar yok | An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior pivotal software · cloud foundry elastic runtime · CWE-532 | Kritik9,8 | — | %1,4 | 13 Haz 2017 |
39İzleyin | CVE-2017-15366İstismar yok | Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.ndocsoftware · ndoc · CWE-532 | Kritik9,8 | — | %1,4 | 26 Eki 2017 |
39İzleyin | CVE-2018-1117İstismar yok | ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Manaovirt · ovirt-ansible-roles · CWE-532 | Kritik9,8 | — | %1,4 | 19 Haz 2018 |
- CVE-2020-3523449Planlayın
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020.
YüksekCVSS 7,5SilahlaştırılmışEPSS %65wp-ecommerce · easy wp smtp13 Ara 2020
- CVE-2025-2498449Planlayın
Windows NTFS Information Disclosure Vulnerability
OrtaCVSS 4,6KEVSilahlaştırılmışEPSS %2microsoft · windows 10 150711 Mar 2025
- CVE-2023-4326148Planlayın
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components
YüksekCVSS 7,5Kavram kanıtıEPSS %60milesight · ur5x firmware4 Eki 2023
- CVE-2023-2149248Planlayın
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
OrtaCVSS 4,4KEVSilahlaştırılmışEPSS %3samsung · android4 May 2023
- CVE-2024-2044046Planlayın
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.
YüksekCVSS 7,5Kavram kanıtıEPSS %52cisco · smart license utility4 Eyl 2024
- CVE-2018-1171643Planlayın
An issue was discovered in Zoho ManageEngine Desktop Central before 100230.
KritikCVSS 9,8İstismar yokEPSS %14zohocorp · manageengine desktop central16 Tem 2018
- CVE-2026-2277842Planlayın
vLLM leaks a heap address when PIL throws an error
KritikCVSS 9,8SilahlaştırılmışEPSS %10vllm · vllm2 Şub 2026
- CVE-2018-1171742Planlayın
An issue was discovered in Zoho ManageEngine Desktop Central before 100251.
KritikCVSS 9,8İstismar yokEPSS %9zohocorp · manageengine desktop central16 Tem 2018
- CVE-2017-755040Planlayın
A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module.
KritikCVSS 9,8İstismar yokEPSS %4redhat · ansible21 Kas 2017
- CVE-2019-388840Planlayın
A vulnerability was found in Undertow web server before 2.0.21.
KritikCVSS 9,8İstismar yokEPSS %3redhat · undertow12 Haz 2019
- CVE-2018-100006040Planlayın
Sensu, Inc.
KritikCVSS 9,8İstismar yokEPSS %2sensu · sensu core9 Şub 2018
- CVE-2021-3272440Planlayın
check-spelling workflow vulnerable to GITHUB_TOKEN leakage via symlink attack
KritikCVSS 9,9Kavram kanıtıEPSS %2check-spelling · check-spelling9 Eyl 2021
- CVE-2017-721440Planlayın
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
KritikCVSS 9,8İstismar yokEPSS %2openstack · nova21 Mar 2017
- CVE-2019-400840Planlayın
API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak.
KritikCVSS 9,8İstismar yokEPSS %2ibm · api connect7 Şub 2019
- CVE-2018-1604940Planlayın
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2.
KritikCVSS 9,8İstismar yokEPSS %2gitlab · gitlab3 Eki 2018
- CVE-2017-807440Planlayın
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadec
KritikCVSS 9,8İstismar yokEPSS %2tp-link · tl-sg108e firmware23 Nis 2017
- CVE-2017-616540Planlayın
In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM, and WebSafe 11.5.1 HF6 through 11.5.4 HF4, 11.6.0 through 1
KritikCVSS 9,8İstismar yokEPSS %2f5 · big-ip access policy manager20 Eki 2017
- CVE-2019-1021240Planlayın
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security.
KritikCVSS 9,8İstismar yokEPSS %2redhat · undertow2 Eki 2019
- CVE-2018-126440Planlayın
Log Cache logs UAA client secret on startup
KritikCVSS 9,8İstismar yokEPSS %2pivotal software · cloud foundry log cache5 Eki 2018
- CVE-2017-807540Planlayın
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext.
KritikCVSS 9,8İstismar yokEPSS %2tp-link · tl-sg108e firmware23 Nis 2017
- CVE-2026-4920040Planlayın
Acer Wave 7 router: Broken Access Control
KritikCVSS 10,0İstismar yokEPSS %1acer · wave 7 firmware29 May 2026
- CVE-2018-100012339İzleyin
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Throu
KritikCVSS 9,8İstismar yokEPSS %1ionicframework · ios keychain13 Mar 2018
- CVE-2017-495539İzleyin
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior
KritikCVSS 9,8İstismar yokEPSS %1pivotal software · cloud foundry elastic runtime13 Haz 2017
- CVE-2017-1536639İzleyin
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password.
KritikCVSS 9,8İstismar yokEPSS %1ndocsoftware · ndoc26 Eki 2017
- CVE-2018-111739İzleyin
ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to Mana
KritikCVSS 9,8İstismar yokEPSS %1ovirt · ovirt-ansible-roles19 Haz 2018