CWE-532

Medium likelihood

Insertion of Sensitive Information into Log File

Parent: CWE-538 - Insertion of Sensitive Information into Externally-Accessible File or Directory

The product writes sensitive information to a log file.

1,170 vulnerabilities with CWE-532
CVE-2025-55285 LOW
@backstage/plugin-scaffolder-backend <2.1.1 - Info Disclosure
CVSS 2.6
CVE-2025-38745 MEDIUM
Dell OpenManage Enterprise 3.10, 4.0, 4.1, 4.2 - Sensitive Information Exposure via Backup and Restore Log
CVSS 4.8
CVE-2025-24520 LOW
Intel(R) Local Manageability Service <2514.7.16.0 - Info Disclosure
CVSS 3.3
CVE-2025-42935 MEDIUM
SAP NetWeaver Application Server ABAP - Info Disclosure
CVSS 4.1
CVE-2025-8864 MEDIUM
Shared Access Signature token exposure - Info Disclosure
CVE-2025-48709 LOW
BMC Control-M/Server 9.0.21.300 - Info Disclosure
CVSS 3.8
CVE-2025-54781 LOW
Himmelblau <1.1.0 - Info Disclosure
CVSS 2.8
CVE-2025-23289 MEDIUM
NVIDIA Omniverse Launcher - Info Disclosure
CVSS 5.5
CVE-2025-30105 HIGH
Dell XtremIO 6.4.0-22 - Info Disclosure
CVSS 8.8
CVE-2025-26332 HIGH
Dell TechAdvisor 2.6-3.37-30 - Insertion of Sensitive Information into Log File
CVSS 8.8
CVE-2025-43225 MEDIUM
iPadOS < 17.7.9 and macOS < 13.7.7, < 14.7.7, < 15.6 - Sensitive Information Disclosure via Log File
CVSS 5.5
CVE-2025-53649 MEDIUM
SwitchBot App for iOS/Android V6.24-V9.12 - Sensitive Information Exposure via Log File Insertion
CVSS 5.1
CVE-2025-54120 CRITICAL
PCL CE <2.12.0-beta.9 - Info Disclosure
CVE-2025-43485 MEDIUM
Poly Clariti Manager <10.12.2 - Info Disclosure
CVSS 4.5
CVE-2025-7371 MEDIUM
Okta On-Premises Provisioning - Info Disclosure
CVSS 6.8
CVE-2025-52580 LOW
Region PAY <1.5.28 - Info Disclosure
CVSS 2.4
CVE-2025-54319 MEDIUM
Westermo WeOS <5.24.4 - Info Disclosure
CVSS 6.3
CVE-2025-6391 CRITICAL
Brocade ASCG < 3.3.0 - Sensitive Information Exposure via JWT Logging
CVSS 9.1
CVE-2025-51497 MEDIUM
AdGuard plugin <1.11.22 - Info Disclosure
CVSS 5.5
CVE-2025-54064 MEDIUM
Rucio helm-charts - Sensitive Information Exposure via Apache Access Log
CVE-2025-30483 MEDIUM
Dell ECS <3.8.1.5/ObjectScale 4.0.0.0 - Info Disclosure
CVSS 5.5
CVE-2025-53886 MEDIUM
Directus 9.0.0-11.8.0 - Sensitive Information Exposure in WebHook Flow Logs
CVSS 4.5
CVE-2025-53885 MEDIUM
Directus 9.0.0-11.8.0 - Sensitive Information Exposure via Log to Console Operation
CVSS 4.2
CVE-2025-6392 MEDIUM
Brocade SANnav < 2.4.0a - Sensitive Information Disclosure in Audit Logs
CVSS 4.4
CVE-2025-36599 MEDIUM
Dell PowerFlex Manager < 4.6.2.1 - Sensitive Information Disclosure via Log File Insertion
CVSS 4.3
Details
Vulnerabilities 1,170
Exploit Likelihood Medium