CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,137 vulnerabilities with CWE-532
CVE-2025-62209 MEDIUM
Windows License Manager - Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-62208 MEDIUM
Windows License Manager - Information Disclosure via Sensitive Data in Log Files
CVSS 5.5
CVE-2025-12940 MEDIUM
NETGEAR WAX610 <10.8.11.4 - Info Disclosure
CVSS 5.5
CVE-2025-11008 CRITICAL
CE21 Suite <2.3.1 - Info Disclosure
CVSS 9.8
CVE-2025-43426 MEDIUM
macOS Tahoe <26.1 - Info Disclosure
CVSS 5.5
CVE-2025-43423 LOW
macOS Tahoe <26.1 - Info Disclosure
CVSS 2.0
CVE-2025-40603 MEDIUM
SonicWall SMA100 Series < 10.2.2.3 - Authenticated Sensitive Information Exposure in Log Files
CVSS 4.5
CVE-2025-62232 HIGH
Apache APISIX < 3.14.0 - Sensitive Data Exposure via Basic-Auth Logging
CVSS 7.5
CVE-2025-58189 MEDIUM
GO < 1.24.8 - Log Information Exposure
CVSS 5.3
CVE-2025-62262 MEDIUM
Liferay DXP 7.4.0-7.4.3.97 & 2023.Q3.1-2023.Q3.4 - Information Exposure via LDAP Logs
CVSS 4.4
CVE-2025-11248 LOW
ZohoCorp ManageEngine Endpoint Central <11.4.2528.05 - Info Disclosure
CVSS 3.2
CVE-2025-11504 HIGH
Quickcreator - AI Blog Writer <0.1.17 - Info Disclosure
CVSS 7.5
CVE-2025-62705 MEDIUM
OpenBao < 2.4.2 - Sensitive Information Disclosure in Audit Log
CVSS 4.9
CVE-2025-62513 HIGH
OpenBao 2.2.0-2.4.1 - Sensitive Information Disclosure in Audit Logs
CVSS 7.5
CVE-2025-46752 MEDIUM
Fortinet FortiDLP <12.0.5 - Info Disclosure
CVSS 4.4
CVE-2025-20329 MEDIUM
Cisco TelePresence CE/RoomOS - Info Disclosure
CVSS 4.9
CVE-2025-10486 MEDIUM
Content Writer <3.6.8 - Info Disclosure
CVSS 5.3
CVE-2025-59258 MEDIUM
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthorized Information Disclosure via ADFS Log File
CVSS 6.2
CVE-2025-59203 MEDIUM
Windows StateRepository API - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-59197 MEDIUM
Windows 10 1507-22H2, Windows 11 22H2-25H2, Windows Server 2016 - Information Disclosure via ETL Channel Log Insertion
CVSS 5.5
CVE-2025-47979 MEDIUM
Microsoft Windows Server 2022 23h2 - Log Information Exposure
CVSS 5.5
CVE-2025-31514 LOW
FortiOS 6.4.0-7.6.3 and FortiProxy 7.0.0-7.6.3 - Sensitive Information Disclosure in Log Files
CVSS 2.7
CVE-2025-37727 MEDIUM
Elasticsearch 7.0.0-7.17.28 and 8.0.0-8.18.7 - Sensitive Information Disclosure in Reindex API Audit Logs
CVSS 5.7
CVE-2025-10645 MEDIUM
WP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via WF_Licensing::log() Method
CVSS 5.3
CVE-2025-36144 LOW
IBM watsonx.data 2.2 - Sensitive Information Exposure in Log Files
CVSS 3.3
Details
Vulnerabilities 1,137
Exploit Likelihood Medium