CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2025-59258 MEDIUM
Windows Server 2012, 2016, 2019, 2022, 2025 - Unauthorized Information Disclosure via ADFS Log File
CVSS 6.2
CVE-2025-59203 MEDIUM
Windows StateRepository API - Sensitive Information Disclosure via Log File Insertion
CVSS 5.5
CVE-2025-59197 MEDIUM
Windows 10 1507-22H2, Windows 11 22H2-25H2, Windows Server 2016 - Information Disclosure via ETL Channel Log Insertion
CVSS 5.5
CVE-2025-47979 MEDIUM
Microsoft Windows Server 2022 23h2 - Log Information Exposure
CVSS 5.5
CVE-2025-31514 LOW
FortiOS 6.4.0-7.6.3 and FortiProxy 7.0.0-7.6.3 - Sensitive Information Disclosure in Log Files
CVSS 2.7
CVE-2025-37727 MEDIUM
Elasticsearch 7.0.0-7.17.28 and 8.0.0-8.18.7 - Sensitive Information Disclosure in Reindex API Audit Logs
CVSS 5.7
CVE-2025-10645 MEDIUM
WP Reset <= 2.05 - Unauthenticated Sensitive Information Exposure via WF_Licensing::log() Method
CVSS 5.3
CVE-2025-36144 LOW
IBM watsonx.data 2.2 - Sensitive Information Exposure in Log Files
CVSS 3.3
CVE-2025-9985 MEDIUM
Featured Image from URL (FIFU) <= 5.2.7 - Unauthenticated Sensitive Information Exposure via Publicly Exposed Log Files
CVSS 5.3
CVE-2025-34188 HIGH
Vasion Print Virtual Appliance Host <1.0.735 & Application <20.0.1330 - Cleartext Session Token Exposure
CVSS 7.8
CVE-2025-34183 HIGH
Ilevia EVE X1 Server <= 4.7.18.0.eden - Unauthenticated Credential Exposure via Log File Disclosure
CVSS 7.5
CVE-2025-43354 MEDIUM
Apple VisionOS <26 - Info Disclosure
CVSS 5.5
CVE-2025-43303 MEDIUM
Apple VisionOS <26 - Info Disclosure
CVSS 5.5
CVE-2025-4234 LOW
Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack - Info Di...
CVE-2025-54376 HIGH
Hoverfly < 1.12.0 - Unauthenticated Sensitive Information Exposure via Admin WebSocket Endpoint
CVSS 7.5
CVE-2025-43888 HIGH
Dell PowerProtect Data Manager < 19.21 - Insertion of Sensitive Information into Log File
CVSS 8.8
CVE-2025-10221 MEDIUM
AxxonSoft Axxon One < 2.0.4 - Sensitive Information Exposure in ARP Agent Log Files
CVSS 5.5
CVE-2025-7445 MEDIUM
Kubernetes secrets-store-sync-controller <0.0.2 - Info Disclosure
CVSS 6.5
CVE-2025-23261 MEDIUM
NVIDIA Cumulus Linux/NVOS - Info Disclosure
CVSS 5.5
CVE-2025-8663 MEDIUM
upKeeper Manager 5.0.0-5.2.11 - Sensitive Information Disclosure in Log Files
CVSS 6.5
CVE-2025-41690 HIGH
Endress+Hauser Promag 10 and Promass 10 - Unauthenticated Sensitive Information Exposure via Event Log
CVSS 7.4
CVE-2025-36133 MEDIUM
IBM App Connect Enterprise 9.2.0-11.6.0, 12.0.0-12.0.14, 12.1.0-12.14.0 - Sensitive Information Exposure
CVSS 5.9
CVE-2025-57813 MEDIUM
traQ < 3.25.0 - Sensitive Information Disclosure in SQL Error Logs
CVSS 5.9
CVE-2025-3456 LOW
Arista EOS 4.29.0-4.34.0F - Sensitive Information Disclosure in Log Files
CVSS 3.8
CVE-2025-7426 CRITICAL
MINOVA TTA - Unauthenticated Exposure of FTP Credentials via Debug Port
Details
Vulnerabilities 1,170
Exploit Likelihood Medium