CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2024-22440 MEDIUM
HPE Compute Scale-up Server 3200 - Info Disclosure
CVSS 6.8
CVE-2024-22339 MEDIUM
IBM UrbanCode Deploy <7.3.2.4 - Info Disclosure
CVSS 4.3
CVE-2024-31391 MEDIUM
Apache Solr Operator 0.3.0-0.8.0 - Sensitive Information Disclosure in Kubernetes Events
CVSS 6.5
CVE-2024-31353 MEDIUM
Tribulant Slideshow Gallery <= 1.7.8 - Sensitive Information Exposure via Log File Insertion
CVSS 5.3
CVE-2024-31298 MEDIUM
Joel Hardi User Spam Remover <= 1.0 - Sensitive Data Exposure via Log File
CVSS 5.3
CVE-2024-31259 HIGH
SearchIQ < 4.5 - Sensitive Data Exposure via Log File
CVSS 7.5
CVE-2024-31254 LOW
WebToffee WordPress Backup & Migration <= 1.4.7 - Sensitive Data Exposure via Log File
CVSS 3.7
CVE-2024-31249 MEDIUM
WPKube Subscribe To Comments Reloaded <= 220725 - Sensitive Information Insertion into Log File
CVSS 5.3
CVE-2024-31247 MEDIUM
Frdric GILLES FG Drupal to WordPress <= 3.70.3 - Sensitive Data Exposure via Log File
CVSS 5.3
CVE-2024-31245 MEDIUM
ConvertKit < 2.4.5 - Sensitive Information Disclosure in Log File
CVSS 5.3
CVE-2024-2302 MEDIUM
Easy Digital Downloads < 3.2.10 - Unauthenticated Sensitive Information Exposure via Debug Log Directory Listing
CVSS 5.3
CVE-2024-25030 MEDIUM
IBM Db2 - Sensitive Information Exposure in Log Files
CVSS 6.2
CVE-2024-3165 MEDIUM
dotcms 22.02-22.03.15 - Authenticated Sensitive Information Exposure in Log Files
CVSS 4.5
CVE-2024-30523 MEDIUM
Paid Memberships Pro - Mailchimp Add On <2.3.4 - Info Disclosure
CVSS 5.3
CVE-2024-30514 MEDIUM
Paid Memberships Pro - Payfast Gateway Add On <1.4.1 - Info Disclosure
CVSS 5.3
CVE-2024-30511 MEDIUM
FG PrestaShop to WooCommerce <4.45.1 - Info Disclosure
CVSS 5.3
CVE-2024-25959 HIGH
Dell PowerScale OneFS 9.4.0.x-9.7.0.x - Sensitive Information Disclosure via Log File Insertion
CVSS 7.9
CVE-2024-25923 MEDIUM
PeepSo Community <6.2.7.0 - Info Disclosure
CVSS 5.3
CVE-2024-22138 MEDIUM
Seraphinite Accelerator <2.20.47 - Info Disclosure
CVSS 5.3
CVE-2024-29945 HIGH
Splunk Enterprise <9.2.1-9.0.9 - Info Disclosure
CVSS 7.2
CVE-2024-25957 MEDIUM
Dell Grab < 5.0.5 - Authenticated Sensitive Information Disclosure in Appsync Module
CVSS 4.8
CVE-2024-24272 HIGH
iTop DualSafe Password Manager < 1.4.24 - Sensitive Information Exposure via Log File
CVSS 7.1
CVE-2024-22352 MEDIUM
IBM InfoSphere Information Server 11.7 - Info Disclosure
CVSS 6.5
CVE-2024-25654 MEDIUM
AVSystem Unified Management Platform 23.07.0.16567~LTS - Sensitive Information Exposure via Log File Permissions
CVSS 5.5
CVE-2024-27097 MEDIUM
CKAN <2.9.11, <2.10.4 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 1,170
Exploit Likelihood Medium