CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2026-25918 MEDIUM
unity-cli < 1.8.2 - Sensitive Credential Exposure in Verbose Logging
CVSS 5.5
CVE-2026-25813 HIGH
PlaciPy 1.0.0 - Sensitive Information Exposure via Console Log
CVSS 7.5
CVE-2026-25846 MEDIUM
JetBrains YouTrack <2025.3.119033 - Info Disclosure
CVSS 6.5
CVE-2026-22038 HIGH
AutoGPT <autogpt-platform-beta-v0.6.46 - Info Disclosure
CVSS 8.1
CVE-2026-1622 MEDIUM
Neo4j < 5.26.21, < 2026.01.3, < 4.4.48 - Information Disclosure in Query Log Error Handling
CVE-2026-24762 HIGH
rustfs 1.0.0-alpha.13-1.0.0-alpha.81 - Sensitive Credential Exposure in Log Files
CVSS 7.5
CVE-2026-22778 CRITICAL
vLLM 0.8.3-0.14.0 - Information Disclosure via Multimodal Endpoint Error Handling
CVSS 9.8
CVE-2026-25211 LOW
llama-stack < 0.4.0rc3 - Sensitive Information Exposure in Initialization Log
CVSS 3.2
CVE-2026-0936 MEDIUM
B&R PVI client < 6.5 - Authenticated Credential Exposure via Log File Insertion
CVSS 5.0
CVE-2026-0519 LOW
Absolute Secure Access 12.70-14.20 - Sensitive Information Exposure in Logging Subsystem
CVSS 3.4
CVE-2026-22782 HIGH
RustFS 1.0.0-alpha.1-1.0.0-alpha.79 - Sensitive Information Exposure via Invalid RPC Signature Logging
CVSS 7.5
CVE-2026-23493 HIGH
Pimcore <12.3.1-11.5.14 - Info Disclosure
CVSS 8.6
CVE-2026-20818 MEDIUM
Windows Server Information Disclosure via Log File Insertion
CVSS 6.2
CVE-2026-22798 MEDIUM
hermes 0.8.1-<0.9.1 - Sensitive Information Disclosure in Log Files via -O Argument
CVSS 5.9
CVE-2025-46313 MEDIUM
macOS < 26.1 - Unprotected User Data Exposure via Logging Issue
CVSS 5.5
CVE-2025-13755 MEDIUM
IBM® Db2® is vulnerable to credential exposure in db2diag when executing specific testcase buckets
CVSS 5.5
CVE-2025-67223 HIGH
Aranda Service Desk <8.3.12 - Info Disclosure
CVSS 7.5
CVE-2025-43937 MEDIUM
Dell PowerScale OneFS <9.12.0.0 - Info Disclosure
CVSS 6.6
CVE-2025-66236 HIGH
Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI
CVSS 7.5
CVE-2025-36187 MEDIUM
Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge
CVSS 4.4
CVE-2025-70040 MEDIUM
jimeng-web-mcp 2.1.2 - Info Disclosure
CVSS 5.3
CVE-2025-62879 MEDIUM
Rancher Backup Operator - Info Disclosure
CVSS 6.8
CVE-2025-48635 HIGH
TaskFragmentOrganizerController - Privilege Escalation
CVSS 7.7
CVE-2025-0976 MEDIUM
Hitachi Ops Center API Config Manager <11.0.4-00 - Info Disclosure
CVSS 4.7
CVE-2025-5781 MEDIUM
Hitachi Ops Center API Config Manager - Info Disclosure
CVSS 5.2
Details
Vulnerabilities 1,137
Exploit Likelihood Medium