VulnSea

CWE-532

CVEs classified under CWE-532, newest first.

118 CVEsRSS

GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

▾ Twilightgeolens · geolensvia GHSA
GHSA-hjwh-xvfw-qrwjMedium· 5.5
1mo ago

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

▾ Sunlitmcp-searxng · mcp-searxngvia GHSA
CVE-2026-66780Medium· 6.5
1mo ago

A flaw was found in the submariner-operator component

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, sp…

▾ SunlitRed Hat · rhacm2/submariner-addon-rhel9EPSS 0.56%via NVD
CVE-2026-75485Medium· 5.5
1mo ago

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This e…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.19%via NVD
CVE-2026-75057Medium· 6.2
1mo ago

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

▾ Sunlitjetbrains · intellij_ideaEPSS 0.17%via NVD
CVE-2026-47234Medium· 4.4
1mo ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment t…

▾ SunlitEPSS 0.17%via NVD
CVE-2026-68969Medium· 6.5
1mo ago

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`)

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking rec…

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-18097Medium· 5.5
1mo ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to obtain sensitive information due to the logging of plain text passwords in trace files.

▾ SunlitEPSS 0.15%via NVD
CVE-2026-71845Medium· 6.3
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to le…

▾ Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.50%via NVD
CVE-2026-71474High· 7.1
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read t…

▾ Twilightredhat · advanced_cluster_management_for_kubernetesEPSS 0.16%via NVD
CVE-2026-18710Medium· 6.5
1mo ago

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatic…

▾ Sunlitmongodb · java_driverEPSS 0.15%via NVD
CVE-2026-46358Medium
1mo ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's inline auth functionality incorrectly redacted audit log entries, resulting in non-auth headers being removed and auth-related headers …

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via NVD
CVE-2026-59326Low· 3.3
1mo ago

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…

▾ Sunlitbroadcom · spring_toolsEPSS 0.14%via NVD
CVE-2026-54704Medium· 6.5
2mo ago

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords

▾ Sunlitopentelemetry · io.opentelemetry.javaagent:opentelemetry-javaagentEPSS 0.38%via GHSA
GHSA-2625-rw7m-5q5xLow
2mo ago

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

Hubuum client library (Rust): Sensitive data may be exposed through default diagnostics

▾ Sunlithubuum_client · hubuum_clientvia GHSA
GHSA-fmvg-vhqq-r2mjMedium
2mo ago

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-65589Medium
2mo ago

n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data

▾ Sunlitn8n · n8nEPSS 0.48%via GHSA
CVE-2026-59947Medium· 4.7
2mo ago

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)

▾ Sunlitcomposer · composer/composerEPSS 0.14%via GHSA
CVE-2026-50316Medium· 5.5
2mo ago

Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.48%via CVEORG
CVE-2026-46467Medium· 5.8
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of …

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of …

▾ SunlitEPSS 0.11%via NVD
CVE-2026-56457Medium· 4.3
3mo ago

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs

HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with access to the logs to potentially obtain sensitive values related to that step.

▾ Sunlithcltechsw · hcl_devops_deployEPSS 0.30%via NVD
GHSA-q683-8468-r6h6Medium
3mo ago

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs

▾ Sunlitweb-auth · web-auth/webauthn-symfony-bundlevia GHSA
CVE-2026-11819Medium· 5.5
3mo ago

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from the OS native keyring (GNOME Keyring, macOS Keychain, Windows Credential Manager) and pl…

▾ Sunlitredhat · enterprise_linuxEPSS 0.16%via NVD
CVE-2026-9073Medium· 6.2
3mo ago

A flaw was found in foreman-mcp-server

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…

▾ Sunlitredhat · satelliteEPSS 0.21%via NVD
CVE-2026-54711Low
3mo ago

PGHoard: Password written to debug log

PGHoard: Password written to debug log

▾ Sunlitpghoard · pghoardvia GHSA
CVE-2026-54236Medium· 5.3PoC
3mo ago

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2026-47768Medium· 5.5
3mo ago

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)

▾ Sunlitjuev · github.com/juev/nebula-meshEPSS 0.15%via GHSA
CVE-2026-0267Medium· 5.5
3mo ago

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app

An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is …

▾ Sunlitpaloaltonetworks · globalprotectEPSS 0.10%via NVD
CVE-2026-32996High· 7.3PoC
4mo ago

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

▾ MidnightVeeam · Backup and ReplicationEPSS 0.14%via NVD
CVE-2026-20239High· 7.5
4mo ago

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session coo…

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session coo…

▾ Twilightsplunk · splunkEPSS 0.48%via NVD
CWE-532 vulnerabilities (CVEs) — page 3 · VulnSea