CWE-532: CWE-532

208
Total CVEs
12
Critical
76
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
29
2025
79
2024
59
2023
18
2022
11

Top Affected Vendors

1 Apple 14
2 Dell 13
3 Ibm 13
4 Microsoft 11
5 Elastic 6
6 Apache 6
7 Broadcom 5
8 Splunk 5
9 Jetbrains 3
10 Fortinet 3

All CWE-532 CVEs (208)

CVE-2025-1296
6.5

Nomad audit logs unintentionally expose sensitive workload identity tokens and client secret tokens. This allows attackers with access to audit logs t...

Mar 10, 2025
CVE-2024-41978
6.5

This vulnerability affects multiple Siemens industrial routers and allows authenticated remote attackers to forge 2FA tokens of other users by extract...

Aug 13, 2024
CVE-2023-25721
6.5

The Veracode Scan Jenkins Plugin before version 23.3.19.0 exposes proxy credentials in job logs when specific configurations are enabled. Users with a...

Mar 28, 2023
CVE-2025-1979
6.4

Ray versions before 2.43.0 log Redis passwords in standard logging when passed as arguments, potentially exposing authentication credentials. This aff...

Mar 6, 2025
CVE-2024-41824
6.4

This vulnerability in JetBrains TeamCity allows password-type parameters to leak into build logs under specific conditions. It affects organizations u...

Jul 22, 2024
CVE-2025-24389
6.3

This vulnerability causes sensitive information to be inadvertently logged and emailed to administrators when upstream library errors occur in OTRS sy...

Jan 27, 2025
CVE-2023-32491
6.3

Dell PowerScale OneFS versions 9.5.0.x have a vulnerability where SNMPv3 logs sensitive information that low-privilege users can access. This allows u...

Aug 16, 2023
CVE-2026-20818
6.2

This vulnerability allows sensitive information to be written to log files in the Windows Kernel, potentially exposing confidential data to local atta...

Jan 13, 2026
CVE-2025-59258
6.2

This vulnerability in Active Directory Federation Services (AD FS) allows unauthorized local attackers to read sensitive information from log files. I...

Oct 14, 2025
CVE-2025-36050
6.2

IBM QRadar SIEM versions 7.5 through 7.5.0 Update Package 12 store sensitive information in log files that local users can read. This information disc...

Jun 19, 2025
CVE-2025-49009
6.2

This vulnerability exposes Facebook user access tokens in plain text within application logs when Facebook authentication requests fail in Para versio...

Jun 5, 2025
CVE-2024-45091
6.2

IBM UrbanCode Deploy versions 7.0 through 7.2.3.13 store sensitive information in HTTP request logs that could be read by local users. This informatio...

Jan 21, 2025
CVE-2023-40694
6.2

IBM Watson CP4D Data Stores versions 4.0.0 through 4.8.4 store sensitive information in log files that could be read by local users. This information ...

May 7, 2024
CVE-2024-6104
6.0

CVE-2024-6104 is an information disclosure vulnerability in go-retryablehttp where URLs containing HTTP basic authentication credentials are written t...

Jun 24, 2024
CVE-2025-37727
5.7

This vulnerability allows sensitive information to be exposed in Elasticsearch log files when auditing requests to the reindex API. Attackers with acc...

Oct 10, 2025
CVE-2025-68919
5.6

This vulnerability in Fujitsu ETERNUS SF management software allows non-admin users to access collected maintenance data, potentially compromising sys...

Dec 24, 2025
CVE-2026-21222
5.5

This vulnerability allows sensitive information to be written to log files in the Windows Kernel. An authenticated attacker with local access could re...

Feb 10, 2026
CVE-2026-25918
5.5

The unity-cli command-line utility logs sensitive credentials (email and password) in plaintext when using the --verbose flag with the sign-package co...

Feb 9, 2026
CVE-2025-43508
5.5

A macOS logging vulnerability allows applications to access sensitive user data that should have been redacted. This affects macOS Tahoe versions befo...

Jan 16, 2026
CVE-2025-43475
5.5

A logging vulnerability in iOS/iPadOS allowed applications to access sensitive user data through insufficient data redaction in system logs. This affe...

Dec 17, 2025
CVE-2025-43538
5.5

This CVE describes a logging data exposure vulnerability in Apple operating systems where applications could access sensitive user data through insuff...

Dec 12, 2025
CVE-2025-14010
5.5

A vulnerability in ansible-collection-community-general exposes plaintext passwords in verbose output when running Ansible with debug modes. Attackers...

Dec 4, 2025
CVE-2025-62209
5.5

Windows License Manager logs sensitive information to local files, allowing authenticated local users to read this data. This affects Windows systems ...

Nov 11, 2025
CVE-2025-62208
5.5

Windows License Manager logs sensitive information to local files, allowing authenticated local attackers to read these logs and potentially obtain cr...

Nov 11, 2025
CVE-2025-12940
5.5

NETGEAR WAX610 and WAX610Y access points inadvertently record login credentials in syslog files when a syslog server is configured. This allows anyone...

Nov 11, 2025
CVE-2025-47979
5.5

This vulnerability allows sensitive information to be written to log files in Windows Failover Cluster. An authenticated attacker with local access co...

Oct 14, 2025
CVE-2025-43354
5.5

A logging vulnerability in Apple operating systems allows applications to access sensitive user data that should have been redacted. This affects user...

Sep 15, 2025
CVE-2025-43303
5.5

This CVE describes a logging vulnerability in Apple operating systems where sensitive user data may not be properly redacted in logs. An application c...

Sep 15, 2025
CVE-2025-23261
5.5

NVIDIA Cumulus Linux and NVOS products log hashed user passwords in log files, potentially exposing credential information to unauthorized users who c...

Sep 4, 2025
CVE-2025-51497
5.5

The AdGuard Safari plugin before version 1.11.22 logged every URL accessed by Safari into macOS system logs, which were readable by any unsandboxed pr...

Jul 17, 2025
CVE-2025-5463
5.5

This vulnerability allows local authenticated attackers to access sensitive information that was improperly logged in Ivanti Connect Secure and Policy...

Jul 8, 2025
CVE-2025-50200
5.5

RabbitMQ versions 3.13.7 and prior log HTTP API authorization headers containing base64-encoded credentials in plaintext. This allows attackers with a...

Jun 19, 2025
CVE-2025-0273
5.5

HCL DevOps Deploy/Launch stores authentication tokens in log files that local users can read. This allows unauthorized access to sensitive credentials...

Mar 27, 2025
CVE-2025-24457
5.5

JetBrains YouTrack versions before 2024.3.55417 expose permanent authentication tokens in application logs. This vulnerability allows attackers with a...

Jan 21, 2025
CVE-2024-11923
5.5

Fortra Application Hub (formerly Helpsystems One) versions before 1.3 log credentials in IAM log files under certain logging configurations. This allo...

Jan 18, 2025
CVE-2025-21320
5.5

This Windows kernel vulnerability allows attackers to read sensitive kernel memory information, potentially exposing system details or credentials. It...

Jan 14, 2025
CVE-2025-21323
5.5

This Windows kernel vulnerability allows attackers to read sensitive memory information from the kernel address space. It affects Windows systems with...

Jan 14, 2025
CVE-2025-21316
5.5

This Windows kernel vulnerability allows attackers to read sensitive memory information from the kernel address space. It affects Windows systems with...

Jan 14, 2025
CVE-2025-21318
5.5

This Windows kernel vulnerability allows attackers to read sensitive memory information from the kernel address space. It affects Windows systems with...

Jan 14, 2025
CVE-2024-40679
5.5

IBM Db2 for Linux, UNIX and Windows (including Db2 Connect Server) version 11.5 may write sensitive information to log files under specific conditions...

Jan 8, 2025
CVE-2024-47094
5.5

This vulnerability in Checkmk monitoring software causes remote site secrets to be written to web log files accessible to local site users. Attackers ...

Nov 29, 2024
CVE-2024-51752
5.5

The AuthKit library for Next.js logs refresh tokens to the console when the debug flag is enabled, potentially exposing sensitive authentication crede...

Nov 5, 2024
CVE-2024-44239
5.5

This CVE describes an information disclosure vulnerability in Apple operating systems where an app could leak sensitive kernel state through log entri...

Oct 28, 2024
CVE-2024-44205
5.5

A sandboxed app on affected Apple operating systems could access sensitive user data from system logs due to insufficient data redaction. This vulnera...

Oct 24, 2024
CVE-2024-44166
5.5

This CVE describes a macOS privacy vulnerability where applications could access sensitive user data from system logs. It affects macOS Ventura, Sonom...

Sep 17, 2024
CVE-2022-25477
5.5

This vulnerability in Realtek card reader drivers leaks kernel memory addresses in driver logs, weakening Kernel Address Space Layout Randomization (K...

Jul 2, 2024
CVE-2023-30430
5.5

This vulnerability in IBM Security Verify Access allows local users to access sensitive information from trace logs. It affects versions 10.0.0 throug...

Jun 27, 2024
CVE-2023-20859
5.5

Spring Vault applications that attempt to revoke Vault batch tokens may inadvertently log sensitive information. This affects applications using Sprin...

Mar 23, 2023
CVE-2026-2605
5.3

Tanium's TanOS logs sensitive information that could be exposed to unauthorized users. This affects organizations using vulnerable Tanium deployments ...

Feb 20, 2026
CVE-2025-10645
5.3

The WP Reset WordPress plugin exposes sensitive license keys and site data when debugging is enabled. This vulnerability affects all versions up to 2....

Oct 7, 2025

About CWE-532 (CWE-532)

Our database tracks 208 CVEs classified as CWE-532, with 12 rated critical and 76 rated high severity. The average CVSS score for CWE-532 vulnerabilities is 6.4.

External reference: View CWE-532 on MITRE CWE →

Monitor CWE-532 Vulnerabilities

Get alerted when new CWE-532 CVEs affect your infrastructure.

Start Monitoring Free