CWE-532: CWE-532

207
Total CVEs
12
Critical
75
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
29
2025
79
2024
59
2023
18
2022
11

Top Affected Vendors

1 Apple 14
2 Dell 13
3 Ibm 13
4 Microsoft 11
5 Elastic 6
6 Apache 6
7 Broadcom 5
8 Splunk 5
9 Jetbrains 3
10 Fortinet 3

All CWE-532 CVEs (207)

CVE-2025-24169
7.5

This vulnerability allows malicious applications to bypass browser extension authentication in Safari by exploiting a logging issue that exposes sensi...

Jan 27, 2025
CVE-2024-8609
7.5

ValeApp versions before 2.0.0 write sensitive information to log files, potentially exposing credentials, tokens, or other confidential data. This aff...

Sep 27, 2024
CVE-2024-34559
7.5

This vulnerability in the Ghost Foundation Ghost WordPress plugin allows sensitive information to be written to log files, potentially exposing creden...

May 14, 2024
CVE-2024-34527
7.5

SolidUI 0.4.0 contains a debug print statement that exposes OpenAI API keys in application logs. This allows anyone with access to logs to steal sensi...

May 6, 2024
CVE-2024-33637
7.5

The Solid Affiliate WordPress plugin versions up to 1.9.1 write sensitive information to log files that could be accessed by unauthorized users. This ...

Apr 29, 2024
CVE-2024-32825
7.5

The Simply Static WordPress plugin versions up to 3.1.3 write sensitive information to log files that could be accessed by unauthorized users. This vu...

Apr 24, 2024
CVE-2024-29957
7.5

Brocade SANnav servers configured in Disaster Recovery mode store encryption keys in DR log files, creating an additional attack surface. Attackers wh...

Apr 19, 2024
CVE-2024-31259
7.5

The SearchIQ WordPress plugin versions up to 4.5 write sensitive information to log files, potentially exposing credentials or other private data. Thi...

Apr 10, 2024
CVE-2023-44989
7.5

This vulnerability in the CF7 Google Sheets Connector WordPress plugin allows sensitive information to be written to debug log files. Attackers can po...

Mar 26, 2024
CVE-2024-23758
7.5

This vulnerability in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information stored in the EnterpriseManagementInstaller_msi.log file...

Feb 20, 2024
CVE-2023-47131
7.5

The N-able PassPortal Chrome extension before version 3.29.2 writes sensitive information to log files, potentially exposing credentials or other conf...

Feb 8, 2024
CVE-2023-6064
7.5

The PayHere Payment Gateway WordPress plugin before version 2.2.12 automatically creates publicly accessible log files containing sensitive transactio...

Jan 1, 2024
CVE-2023-47390
7.5

Headscale versions through 0.22.3 write bearer tokens to info-level logs, exposing authentication credentials. This affects all Headscale deployments ...

Nov 11, 2023
CVE-2023-46215
7.5

Apache Airflow and its Celery provider versions 1.10.0-2.6.3 and 3.3.0-3.4.0 log sensitive information in clear text when using rediss, amqp, or rpc p...

Oct 28, 2023
CVE-2023-5499
7.5

This vulnerability allows remote attackers to access sensitive information from Shenzhen Reachfar v28 devices by retrieving log files from the 'log2' ...

Oct 10, 2023
CVE-2023-35695
7.5

This vulnerability allows remote attackers to download log files containing sensitive information from Trend Micro Mobile Security (Enterprise). Attac...

Jun 26, 2023
CVE-2023-22362
7.5

The SUSHIRO Android app logs sensitive credential information to device log files, allowing attackers with physical or remote access to the device to ...

Feb 13, 2023
CVE-2021-36544
7.5

CVE-2021-36544 is an incorrect access control vulnerability in tpcms 3.2 that allows remote attackers to view sensitive information by manipulating pa...

Feb 3, 2023
CVE-2022-32556
7.5

CVE-2022-32556 is a sensitive information disclosure vulnerability in Couchbase Server where private keys are written to log files during certain cras...

Jul 21, 2022
CVE-2022-32565
7.5

CVE-2022-32565 is an information disclosure vulnerability in Couchbase Server where the Backup Service logs contain unredacted usernames and document ...

Jun 13, 2022
CVE-2022-27442
7.5

CVE-2022-27442 allows attackers to access ThinkPHP log directories in TPCMS v3.2, potentially exposing administrator credentials and other sensitive i...

Apr 4, 2022
CVE-2022-24758
7.5

This vulnerability in Jupyter Notebook allows unauthorized actors to access sensitive authentication cookies and header values from server logs when 5...

Mar 31, 2022
CVE-2022-27192
7.5

CVE-2022-27192 is an information disclosure vulnerability in the Reporting module of Aseco Lietuva's DVS Avilys document management system. It allows ...

Mar 23, 2022
CVE-2022-24757
7.5

CVE-2022-24757 allows unauthorized actors to access sensitive authentication information from Jupyter Server logs when 5xx errors occur. This affects ...

Mar 23, 2022
CVE-2022-25374
7.5

HashiCorp Terraform Enterprise versions v202112-1 through v202201-2 log inbound HTTP requests in a way that may capture sensitive data like credential...

Feb 25, 2022
CVE-2021-34797
7.5

Apache Geode versions up to 1.12.4 and 1.13.4 fail to properly redact sensitive information in log files when passwords or security properties begin w...

Jan 4, 2022
CVE-2021-34800
7.5

Acronis Agent versions before build 27147 on Windows, Linux, and macOS can log sensitive information to system logs. This vulnerability allows attacke...

Nov 29, 2021
CVE-2020-21933
7.5

Motorola CX2 router firmware versions including Build 20190508 Rel.97360n store admin passwords and private keys in log files that are included in tar...

Jul 21, 2021
CVE-2020-23284
7.5

CVE-2020-23284 is an information disclosure vulnerability in MV's IDCE application v1.0 that allows unauthenticated attackers to access sensitive data...

Jul 20, 2021
CVE-2021-35299
7.5

This vulnerability in Zammad allows attackers to probe email connection configurations and obtain sensitive information like email server credentials....

Jun 28, 2021
CVE-2021-22516
7.5

CVE-2021-22516 is a sensitive information disclosure vulnerability in Micro Focus Secure API Manager (SAPIM) version 2.0.0 where sensitive data like c...

Jun 4, 2021
CVE-2025-6624
7.2

Snyk CLI versions before 1.1297.3 expose sensitive credentials in debug logs when running in DEBUG or TRACE mode. This affects users who run Snyk cont...

Jun 26, 2025
CVE-2024-29945
7.2

Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9 may expose authentication tokens during validation when debug logging is enabled. This allows...

Mar 27, 2024
CVE-2025-36573
7.1

Dell Smart Dock Firmware versions before 01.00.08.01 write sensitive information to log files that local users can read. This allows information discl...

Jun 12, 2025
CVE-2025-20231
7.1

This vulnerability allows low-privileged Splunk users to run searches with higher-privileged user permissions through a phishing attack, potentially e...

Mar 26, 2025
CVE-2024-24272
7.1

A vulnerability in iTop DualSafe Password Manager & Digital Vault allows local attackers to access sensitive credentials stored in plaintext within lo...

Mar 21, 2024
CVE-2024-28186
7.1

This vulnerability in FreeScout exposes SMTP server credentials to authenticated users through stack traces stored in the database and accessible via ...

Mar 12, 2024
CVE-2025-62879
6.8

CVE-2025-62879 is a sensitive information disclosure vulnerability in Rancher Backup Operator where S3 access tokens (accessKey and secretKey) are lea...

Mar 4, 2026
CVE-2026-20144
6.8

This vulnerability allows authenticated users with access to Splunk's _internal index to view SAML configuration data in plain text within log files. ...

Feb 18, 2026
CVE-2026-20138
6.8

This vulnerability allows users with access to Splunk's _internal index to view sensitive authentication secrets in plain text. Specifically, Duo Two-...

Feb 18, 2026
CVE-2022-43936
6.8

Brocade SANnav versions before 2.2.2 log switch passwords in plaintext when debugging is enabled. This allows attackers with access to logs to obtain ...

Nov 21, 2024
CVE-2024-32757
6.8

CVE-2024-32757 is an information disclosure vulnerability in Johnson Controls Metasys products where system logs inadvertently contain sensitive user ...

Jul 2, 2024
CVE-2024-27157
6.8

This vulnerability allows attackers to retrieve authentication sessions from clear-text logs, potentially enabling credential theft and authentication...

Jun 14, 2024
CVE-2024-47570
6.6

This vulnerability allows read-only administrators to retrieve API tokens of other administrators by examining REST API logs when REST API logging is ...

Dec 9, 2025
CVE-2026-1292
6.5

Tanium Trends logs sensitive information that should not be exposed. This vulnerability affects organizations using Tanium Trends who have access to l...

Feb 20, 2026
CVE-2026-25846
6.5

JetBrains YouTrack versions before 2025.3.119033 expose access tokens in Mailbox logs, potentially allowing attackers to steal authentication credenti...

Feb 9, 2026
CVE-2025-64650
6.5

IBM Storage Defender - Resiliency Service versions 2.0.0 through 2.0.18 write sensitive user credentials to log files. This allows attackers with acce...

Dec 8, 2025
CVE-2025-8663
6.5

This vulnerability in upKeeper Manager logs sensitive domain credentials in log files, potentially exposing authentication information. Attackers who ...

Sep 3, 2025
CVE-2025-27391
6.5

Apache ActiveMQ Artemis versions 1.5.1 through 2.39.0 log sensitive broker configuration properties when debug logging is enabled. This exposes creden...

Apr 9, 2025
CVE-2025-1296
6.5

Nomad audit logs unintentionally expose sensitive workload identity tokens and client secret tokens. This allows attackers with access to audit logs t...

Mar 10, 2025

About CWE-532 (CWE-532)

Our database tracks 207 CVEs classified as CWE-532, with 12 rated critical and 75 rated high severity. The average CVSS score for CWE-532 vulnerabilities is 6.4.

External reference: View CWE-532 on MITRE CWE →

Monitor CWE-532 Vulnerabilities

Get alerted when new CWE-532 CVEs affect your infrastructure.

Start Monitoring Free