VulnSea

CWE-532

CVEs classified under CWE-532, newest first.

118 CVEsRSS

CVE-2026-41219Medium· 6.5
4mo ago

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which have reached End of Technical Support (E…

An improper sanitization vulnerability exists in the BIG-IP QKView utility that allows a low-privileged attacker to read sensitive information from a QKView file.  Note: Software versions which have reached End of Technical Support (E…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-32217Medium· 5.5
5mo ago

Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1607EPSS 0.48%via CVEORG
CVE-2026-32215Medium· 5.5
5mo ago

Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 1809EPSS 0.48%via CVEORG
CVE-2026-32218Medium· 5.5
5mo ago

Windows Kernel Information Disclosure Vulnerability

Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.

▾ SunlitMicrosoft · Windows 10 Version 21H2EPSS 0.50%via CVEORG
CVE-2025-66236High· 7.5
5mo ago

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager …

▾ TwilightApache Software Foundation · apache-airflowEPSS 0.44%via CVEORG
CVE-2026-4901Medium· 6.5
5mo ago

AlanWeb SCADA saves sensitive information into a log file

AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive inf…

▾ Sunlithydrosystem.poznan · control_systemEPSS 0.40%via NVD
CVE-2026-32982High· 7.5
6mo ago

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages

OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tok…

▾ Twilightopenclaw · openclawEPSS 0.51%via NVD
CVE-2026-4819Medium· 4.9
6mo ago

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.

▾ Sunlitsearch-guard · flxEPSS 0.36%via NVD
CVE-2026-0520Low· 2.8
6mo ago

A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file.

▾ Sunlitlenovo · filezEPSS 0.09%via NVD
CVE-2026-24308High· 7.5⚖ disputed
6mo ago

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values ar…

▾ Twilightapache · zookeeperEPSS 1.2%via NVD
CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

▾ Abyssalvllm · vllmEPSS 3.8%via NVD
CVE-2025-12996Medium· 4.1
9mo ago

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. This issue affects CareLink Network: before December 4, 2025.

▾ Sunlitmedtronic · carelink_networkEPSS 0.11%via NVD
CVE-2025-43426Medium· 5.5PoC
10mo ago

A logging issue was addressed with improved data redaction

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

▾ Twilightapple · ipadosEPSS 0.26%via NVD
CVE-2025-43423Low· 2.0
10mo ago

A logging issue was addressed with improved data redaction

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical access to an unlo…

▾ Sunlitapple · ipadosEPSS 0.23%via NVD
CVE-2025-10221Medium· 5.5
1y ago

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via readin…

Insertion of Sensitive Information into Log File (CWE-532) in the ARP Agent component in AxxonSoft Axxon One / AxxonNet / C-WerkNet 2.0.4 and earlier on Windows platforms allows a local attacker to obtain plaintext credentials via readin…

▾ Sunlitaxxonsoft · axxon_oneEPSS 0.13%via NVD
CVE-2024-9621Medium· 5.3
1y ago

A vulnerability was found in Quarkus CXF

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP lo…

▾ SunlitEPSS 0.52%via NVD
CVE-2024-8775Medium· 5.5
2y ago

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook

A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without se…

▾ SunlitRed Hat · ansible-coreEPSS 0.27%via NVD
CVE-2024-31249Medium· 5.3
2y ago

Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

Insertion of Sensitive Information into Log File vulnerability in WPKube Subscribe To Comments Reloaded.This issue affects Subscribe To Comments Reloaded: from n/a through 220725.

▾ Sunlitwpkube · subscribe_to_comments_reloadedEPSS 0.51%via NVD
CVE-2024-31245Medium· 5.3
2y ago

Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.

Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.

▾ Sunlitconvertkit · convertkit_-_email_marketing,_email_newsletter_and_landing_pagesEPSS 0.52%via NVD
CVE-2023-51702Medium· 6.5
2y ago

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in met…

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in met…

▾ Sunlitapache · airflowEPSS 0.39%via NVD
CVE-2024-23686Medium· 5.3
2y ago

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.

▾ Sunlitowasp · dependency-checkEPSS 0.60%via NVD
CVE-2023-43261High· 7.5PoC
2y ago

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.

▾ Midnightmilesight · ur5x_firmwareEPSS 60%via NVD
CVE-2022-4311Medium· 4.7
3y ago

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2

An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConne…

▾ Sunlitarcinfo · pcvueEPSS 0.34%via NVD
CVE-2022-31684Medium· 4.3
3y ago

Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests

Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs. This may affect only invalid H…

▾ Sunlitbroadcom · reactor_nettyEPSS 0.66%via NVD
CVE-2017-17675Medium· 5.3
5y ago

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking

BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.

▾ Sunlitbmc · remedy_mid-tierEPSS 0.87%via NVD
CVE-2019-1961Medium· 4.9
7y ago

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device

A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to the …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 1.9%via NVD
CVE-2019-1953Medium· 6.5
7y ago

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text

A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text. The vulnerability is due to incorrectly logging the admin password …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 1.5%via NVD
CVE-2017-16946Medium· 4.9
8y ago

The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.

The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the audit log.

▾ Sunlitmisp-project · mispEPSS 1.1%via NVD
CWE-532 vulnerabilities (CVEs) — page 4 · VulnSea