VulnSea

CWE-532

CVEs classified under CWE-532, newest first.

96 CVEsRSS

CVE-2026-49810High· 7.8
today

Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability

Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leadin…

TwilightDell · Command Powershell Provider (DCPP)via CVEORG
CVE-2026-93982Low· 3.3PoC
2d ago

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems c…

TwilightOpenpanel-dev · openpanelEPSS 0.11%via NVD
CVE-2026-86049High· 7.1
4d ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…

Twilightjupyter-server · jupyter_serverEPSS 0.24%via NVD
CVE-2026-92758Medium· 5.5
4d ago

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

SunlitMongoDB Inc. · MongoDB Entity Framework Core ProviderEPSS 0.11%via NVD
CVE-2026-82723Low· 1.8
4d ago

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

Sunlitteam-alembic · ash_authenticationEPSS 0.14%via NVD
CVE-2026-92918High· 8.8PoC
4d ago

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens…

Midnightcjbi · admin3EPSS 0.35%via NVD
CVE-2026-81870Low· 2.0PoC
5d ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-73442Low· 3.0
5d ago

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a s…

On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials are logged in cleartext on the switch, allowing an authenticated user with sufficient privileges to view agent trace logs (or a s…

SunlitArista Networks · EOSEPSS 0.21%via NVD
CVE-2026-73457Medium· 5.3
5d ago

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authentica…

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, the gNPSI client credentials might be logged in clear text in local or remote accounting logs to authentica…

SunlitArista Networks · EOSEPSS 0.32%via NVD
CVE-2026-92237Medium· 6.5
6d ago

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protecti…

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protecti…

SunlitDevolutions · PowerShell UniversalEPSS 0.27%via NVD
CVE-2026-73467Medium· 6.3
6d ago

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

SunlitArista Networks · EOSEPSS 0.09%via NVD
CVE-2026-73466Medium· 6.3
6d ago

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit th…

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit th…

SunlitArista Networks · EOSEPSS 0.09%via NVD
CVE-2026-73465Medium· 6.3
6d ago

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exp…

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exp…

SunlitArista Networks · EOSEPSS 0.09%via NVD
CVE-2026-81320Medium· 5.5
6d ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and wri…

SunlitRed Hat · rhbac-4/hawtio-rhel9EPSS 0.14%via NVD
CVE-2026-84527Medium· 5.5
1w ago

A logging issue was addressed with improved data redaction

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app may be able to access sensitive…

Sunlitapple · ipadosEPSS 0.13%via NVD
CVE-2026-84513Medium· 5.5
1w ago

A privacy issue was addressed with improved private data redaction for log entries

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, …

Sunlitapple · ipadosEPSS 0.16%via NVD
CVE-2026-84525Medium· 5.5
1w ago

A logging issue was addressed with improved data redaction

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access user-sensitive data.

Sunlitapple · macosEPSS 0.12%via NVD
CVE-2026-87779High· 7.5
1w ago

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key va…

TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.41%via NVD
CVE-2026-82434Medium· 6.5⚖ disputed
1w ago

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any ca…

SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.48%via NVD
CVE-2026-55102Medium· 5.8
1w ago

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosEr…

Sunlitkyndryl-open-source · hashi-vault-jsEPSS 0.11%via NVD
CVE-2026-87993High· 7.7
1w ago

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

TwilightHashiCorp · ToolingEPSS 0.27%via NVD
CVE-2026-88883High· 7.7⚖ disputed
1w ago

Renovate is an automated dependency update tool

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for …

Twilightrenovatebot · renovateEPSS 0.28%via NVD
CVE-2026-80124Medium· 5.5
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.10%via CVEORG
CVE-2026-79966Low· 3.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

Sunlitdell · secure_connect_gatewayEPSS 0.10%via NVD
CVE-2026-80169Low· 3.3
1w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

Sunlitdell · secure_connect_gatewayEPSS 0.10%via NVD
CVE-2025-46808Medium· 6.8
1w ago

An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.

An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive information into the manager container’s log This issue affects neuvector: before 5.4.5.

SunlitSUSE · managerEPSS 0.20%via NVD
CVE-2026-78631Medium· 5.3
1w ago

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authen…

SunlitOkta · Okta Hyperdrive AgentEPSS 0.10%via NVD
CVE-2026-78627High· 7.3
1w ago

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of…

TwilightOkta · Okta Hyperdrive Integration PluginEPSS 0.10%via NVD
CVE-2026-68873Medium· 5.5
1w ago

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.

Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_11_23h2EPSS 0.46%via NVD
CVE-2026-86597Medium· 6.5
1w ago

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be…

SunlitSnowflake · snowflake-connector-pythonEPSS 0.09%via NVD
CWE-532 vulnerabilities (CVEs) · VulnSea