VulnSea

CWE-532

CVEs classified under CWE-532, newest first.

96 CVEsRSS

CVE-2026-86501Low· 2.8
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log

SunlitJetBrains · IntelliJ IDEAEPSS 0.27%via NVD
CVE-2026-80056Medium· 5.5
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

Sunlitdell · secure_connect_gatewayEPSS 0.10%via NVD
CVE-2026-17442Medium· 5.1
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being writte…

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to credentials being writte…

Sunlitibm · app_connect_enterpriseEPSS 0.09%via NVD
CVE-2026-19649Medium· 6.2
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of data…

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of data…

Sunlitibm · app_connect_enterpriseEPSS 0.11%via NVD
CVE-2026-16689Medium· 6.2
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of cred…

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of cred…

Sunlitibm · app_connect_enterpriseEPSS 0.11%via NVD
CVE-2026-85171Medium· 6.5
2w ago

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes

n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailcheck nodes. These nodes send their decrypted credentials to the authentication endpoint via the raw legacy HTTP helper…

Sunlitn8n · n8nEPSS 0.32%via NVD
CVE-2026-85174High· 8.8
2w ago

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds

SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover …

TwilightEPSS 0.30%via NVD
CVE-2026-55221Medium· 6.5
2w ago

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, Boruta logged sensitive OAuth and OpenID Connect values in business eve…

Sunlitmalach-it · boruta-serverEPSS 0.27%via NVD
CVE-2026-55785Low· 3.7
3w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAk…

Sunlitfree5gc · github.com/free5gc/ausfEPSS 0.28%via NVD
CVE-2026-81715Low· 3.3
3w ago

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to saniti…

openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positional argument to 'keyserver set-token' in the --debug argv dump, because sanitize_argv_for_debug fails to saniti…

Sunlitjahlives · openssl_encryptEPSS 0.19%via NVD
CVE-2026-59302Low· 3.1
3w ago

Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

SunlitRed HatEPSS 0.15%via NVD
CVE-2026-59301Low· 3.1
3w ago

Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7

Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7

SunlitEPSS 0.17%via NVD
CVE-2026-59300Low· 3.1
3w ago

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

SunlitEPSS 0.15%via NVD
CVE-2026-61798High· 8.1
1mo ago

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages

Twilightnetty · io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringsslvia GHSA
CVE-2020-37267High· 7.5
1mo ago

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without redaction. Anyone with…

TwilightEPSS 0.31%via NVD
CVE-2019-25766High· 7.5
1mo ago

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is fixed in version 19.38.7. Anyone able to view the affected pull requ…

TwilightEPSS 0.31%via NVD
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

Twilightgeolens · geolensvia GHSA
GHSA-hjwh-xvfw-qrwjMedium· 5.5
1mo ago

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

Sunlitmcp-searxng · mcp-searxngvia GHSA
CVE-2026-66780Medium· 6.5
1mo ago

A flaw was found in the submariner-operator component

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, sp…

SunlitRed Hat · rhacm2/submariner-addon-rhel9EPSS 0.24%via NVD
CVE-2026-75485Medium· 5.5
1mo ago

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This e…

SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.14%via NVD
CVE-2026-75057Medium· 6.2
1mo ago

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

Sunlitjetbrains · intellij_ideaEPSS 0.13%via NVD
CVE-2026-47234Medium· 4.4
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment t…

SunlitEPSS 0.13%via NVD
CVE-2026-68969Medium· 6.5
1mo ago

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`)

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking rec…

Sunlitapache · airflowEPSS 0.36%via NVD
CVE-2026-18097Medium· 5.5
1mo ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.

SunlitEPSS 0.11%via NVD
CVE-2026-71845Medium· 6.3
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to le…

Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.28%via NVD
CVE-2026-71474High· 7.1
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read t…

Twilightredhat · advanced_cluster_management_for_kubernetesEPSS 0.11%via NVD
CVE-2026-18710Medium· 6.5
1mo ago

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatic…

SunlitRed Hat · Red Hat build of Apache Camel 4 for Quarkus 3EPSS 0.12%via NVD
CVE-2026-46358Medium
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.23%via NVD
CVE-2026-59326Low· 3.3
1mo ago

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…

Sunlitbroadcom · spring_toolsEPSS 0.10%via NVD
CVE-2026-54704Medium· 6.5
1mo ago

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

Sunlitopentelemetry · io.opentelemetry.javaagent:opentelemetry-javaagentEPSS 0.38%via GHSA
CWE-532 vulnerabilities (CVEs) — page 2 · VulnSea