CWE-532
1,164 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
CVEs (1,164)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 2Wax610 Firmware Wax610y FirmwareJun 17, 2026 Nov 11, 2025 0.5 LOW· v4 5.5 MEDIUM· v3 N/A· v2 Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig Insight Managed WiFi 6 Access Points). An user having access to the sysl...Show more |
The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauthenticated attackers to extract sensitive...Show more |
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data. |
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Tahoe 26.1, visionOS 26.1. An attacker with physical...Show more |
1Sonicwall 3Sma 210 Firmware Sma 410 FirmwareSma 500v FirmwareJun 17, 2026 Oct 31, 2025 N/A· v4 4.5 MEDIUM· v3 N/A· v2 A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data. |
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromis...Show more |
When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped. |
A vulnerability has been identified in Rancher Manager, where sensitive
information, including secret data, cluster import URLs, and
registration tokens, is exposed to any entity with access to Rancher
audit logs. |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 Oct 27, 2025 4.6 MEDIUM· v4 4.4 MEDIUM· v3 N/A· v2 Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92,...Show more |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Oct 27, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent to...Show more |
The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dupasrala.txt file. This makes it possible f...Show more |
OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent []byte response parameters rather than str...Show more |
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few endpoints were not correctly redacted (HMAC...Show more |
A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code. |
1Cisco 2Roomos Telepresence Collaboration EndpointJun 17, 2026 Oct 15, 2025 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affecte...Show more |
The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes it possible for unauthenticated attackers...Show more |
1Microsoft 6Windows Server 2012 Windows Server 2016Windows Server 2019+3 moreJun 17, 2026 Oct 14, 2025 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally. |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Oct 14, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJun 17, 2026 Oct 14, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. |
1Microsoft 2Windows Server 2022 23h2 Windows Server 2025Jun 17, 2026 Oct 14, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. |