CWE-532: CWE-532

208
Total CVEs
12
Critical
76
High
6.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
29
2025
79
2024
59
2023
18
2022
11

Top Affected Vendors

1 Apple 14
2 Dell 13
3 Ibm 13
4 Microsoft 11
5 Elastic 6
6 Apache 6
7 Broadcom 5
8 Splunk 5
9 Jetbrains 3
10 Fortinet 3

All CWE-532 CVEs (208)

CVE-2025-9985
5.3

The Featured Image from URL WordPress plugin exposes sensitive information through publicly accessible log files in versions up to 5.2.7. Unauthentica...

Sep 26, 2025
CVE-2025-31788
5.3

This vulnerability allows attackers to retrieve sensitive data embedded in log files generated by the AIO Performance Profiler WordPress plugin. It af...

Apr 1, 2025
CVE-2024-38321
5.3

IBM Business Automation Workflow versions 22.0.2 through 24.0.0 store sensitive information in log files that authenticated users can read. This infor...

Aug 3, 2024
CVE-2024-42349
5.3

FOG Server versions 1.5.10.41.4 and earlier store login logs in publicly accessible web server directories, exposing usernames, IP addresses, and user...

Aug 2, 2024
CVE-2024-40636
5.3

This vulnerability in Steeltoe's Eureka discovery client logs authentication credentials when multiple Eureka server URLs with basic authentication ar...

Jul 17, 2024
CVE-2024-37205
5.3

This vulnerability in the WordPress Affiliate Toolkit plugin causes sensitive information to be written to log files, potentially exposing credentials...

Jul 10, 2024
CVE-2024-22276
5.3

VMware Cloud Director Object Storage Extension logs sensitive information in URLs, which could be exposed through web/proxy server logs. Attackers wit...

Jun 27, 2024
CVE-2022-44587
5.3

The WP 2FA WordPress plugin versions up to 2.6.3 write sensitive information to log files that should be protected. This allows attackers with access ...

Jun 21, 2024
CVE-2024-32811
5.3

This vulnerability allows sensitive information to be written to log files in the Octolize USPS Shipping for WooCommerce plugin. Attackers could poten...

Jun 9, 2024
CVE-2024-34798
5.3

The Debug Log - Manger Tool WordPress plugin versions up to 1.4.5 can write sensitive information like passwords or API keys to log files. This affect...

Jun 3, 2024
CVE-2024-34550
5.3

The AlexaCRM Dynamics 365 Integration WordPress plugin versions up to 1.3.17 write sensitive information to log files, potentially exposing credential...

May 14, 2024
CVE-2025-5781
5.2

This vulnerability allows session hijacking through information exposure in Hitachi management software. Attackers can intercept or access session dat...

Feb 25, 2026
CVE-2023-49921
5.2

This CVE allows sensitive Elasticsearch document contents to be exposed in application logs when Watcher search input is configured with DEBUG logging...

Jul 26, 2024
CVE-2022-35202
5.1

This vulnerability allows remote attackers to download the Java keystore containing SAML signing private keys via WebDAV in non-default configurations...

Feb 11, 2025
CVE-2024-31216
5.1

The source-controller Kubernetes operator logs Azure SAS tokens when connection errors occur with Azure Blob Storage. Attackers with access to these l...

May 15, 2024
CVE-2026-0936
5.0

An authenticated local attacker can exploit this vulnerability in B&R PVI client versions prior to 6.5 to gather credential information from log files...

Jan 29, 2026
CVE-2025-15332
4.9

An information disclosure vulnerability in Tanium Threat Response could allow authenticated users to access sensitive data they shouldn't have permiss...

Feb 5, 2026
CVE-2025-13925
4.9

IBM Aspera Console 3.4.7 stores sensitive information in log files that could be accessed by local privileged users. This vulnerability allows attacke...

Jan 20, 2026
CVE-2025-14432
4.9

Microsoft Teams Admin Center may write sensitive data to log files when administrators make device configuration changes. Only users with admin creden...

Dec 16, 2025
CVE-2025-20329
4.9

This vulnerability allows authenticated administrators on Cisco TelePresence and RoomOS systems to view unencrypted credentials in audit logs when SIP...

Oct 15, 2025
CVE-2025-0071
4.9

SAP Web Dispatcher and Internet Communication Manager allow administrators to enable debugging trace mode with a specific parameter, exposing unencryp...

Mar 11, 2025
CVE-2025-1053
4.9

During SANnav installation or upgrade error conditions, the encryption key can be written to and retrieved from a supportsave file. Attackers with pri...

Feb 14, 2025
CVE-2024-49816
4.9

IBM Security Guardium Key Lifecycle Manager versions 4.1 through 4.2.1 store sensitive information in log files that could be read by local privileged...

Dec 17, 2024
CVE-2024-52067
4.9

Apache NiFi versions 1.16.0-1.28.0 and 2.0.0-M1-2.0.0-M4 have debug logging that can expose sensitive parameter values when enabled. Authorized admini...

Nov 21, 2024
CVE-2025-38745
4.8

Dell OpenManage Enterprise versions 3.10 through 4.2 contain a vulnerability where sensitive information is written to log files during backup and res...

Aug 14, 2025
CVE-2025-0976
4.7

This CVE describes an information exposure vulnerability in Hitachi Ops Center API Configuration Manager and Hitachi Configuration Manager. The vulner...

Feb 25, 2026
CVE-2025-24984
KEV 4.6

This vulnerability allows sensitive information to be written to Windows NTFS log files, which could be accessed by an attacker with physical access t...

Mar 11, 2025
CVE-2025-40603
4.5

A vulnerability in SonicWall SMA100 Series appliances may expose partial user credential data in log files under certain conditions. This allows remot...

Oct 31, 2025
CVE-2024-5557
4.5

This vulnerability exposes SNMP credentials in log files due to sensitive information being written to logs. Attackers who gain access to controller l...

Jun 12, 2024
CVE-2025-62262
4.4

This vulnerability allows local users to view user email addresses in log files through the LDAP import feature in Liferay Portal and DXP. It affects ...

Oct 27, 2025
CVE-2025-46752
4.4

This vulnerability in Fortinet FortiDLP allows attackers to obtain sensitive information by reusing enrollment codes that were improperly logged. It a...

Oct 16, 2025
CVE-2024-7577
4.4

IBM InfoSphere Information Server 11.7 may expose sensitive user credentials in log files during new installations. This vulnerability allows attacker...

Mar 29, 2025
CVE-2025-23413
4.4

BIG-IP Next Central Manager logs sensitive authentication information in pgaudit log files when users log in via webUI or API using local authenticati...

Feb 5, 2025
CVE-2023-46175
4.4

IBM Cloud Pak for Multicloud Management versions 2.3 through 2.3 FP8 store user credentials in plain text within log files. This allows privileged use...

Sep 26, 2024
CVE-2024-42344
4.4

SINEMA Remote Connect Client versions before V3.2 SP2 write sensitive configuration data to log files that are readable by all legitimate system users...

Sep 10, 2024
CVE-2022-4858
4.4

M-Files Server versions before 22.10.11846.0 can log sensitive authentication tokens to log files when specific configurations are enabled. This vulne...

Dec 30, 2022
CVE-2026-1265
4.3

IBM InfoSphere Information Server versions 11.7.0.0 through 11.7.1.6 write sensitive information to log files, potentially exposing credentials or oth...

Mar 3, 2026
CVE-2024-58269
4.3

Rancher Manager exposes sensitive information including secrets, cluster import URLs, and registration tokens in audit logs accessible to any user wit...

Oct 29, 2025
CVE-2023-38271
4.3

This vulnerability in IBM Cloud Pak System allows authenticated users to access sensitive information from log files. It affects multiple versions of ...

Jan 25, 2025
CVE-2024-40596
4.3

The CheckUser extension for MediaWiki has a vulnerability where the Special:Investigate feature can expose suppressed log event information that shoul...

Jul 7, 2024
CVE-2024-47822
4.2

Directus systems with LOG_STYLE set to 'raw' expose access tokens in query strings within system logs. Attackers with log access can steal these token...

Oct 8, 2024
CVE-2024-41719
4.2

This vulnerability exposes F5 iHealth credentials in BIG-IP Central Manager logs when generating QKView diagnostic files from BIG-IP Next instances. T...

Aug 14, 2024
CVE-2024-0912
4.2

This vulnerability causes Microsoft IIS servers hosting Cβ€’CURE 9000 Web Server to log Windows credential details in log files under certain circumst...

Jun 6, 2024
CVE-2023-28630
4.2

GoCD versions 20.5.0 through 23.1.0 can leak database credentials in admin alerts when backups are enabled but required database dump utilities are mi...

Mar 27, 2023
CVE-2025-12996
4.1

Medtronic CareLink Network logs plaintext passwords in error messages under certain conditions, allowing local attackers with access to API server log...

Dec 4, 2025
CVE-2025-42935
4.1

CVE-2025-42935 allows authorized administrators with local file system access to read sensitive information from SAP NetWeaver ICM log files. This vul...

Aug 12, 2025
CVE-2024-51528
4.0

This vulnerability involves improper log printing in Huawei's Super Home Screen module, potentially exposing sensitive information in log files. It af...

Nov 5, 2024
CVE-2024-4472
4.0

This vulnerability exposes dependency proxy credentials in GraphQL logs in GitLab instances. Attackers with access to these logs could obtain credenti...

Sep 12, 2024
CVE-2026-0519
3.4

Secure Access versions 12.70 through 14.20 may write unredacted authentication tokens to logs under certain configurations. Attackers with access to t...

Jan 17, 2026
CVE-2026-20663
3.3

This vulnerability allows malicious apps to enumerate a user's installed applications on iOS and iPadOS devices. It affects users running vulnerable v...

Feb 11, 2026

About CWE-532 (CWE-532)

Our database tracks 208 CVEs classified as CWE-532, with 12 rated critical and 76 rated high severity. The average CVSS score for CWE-532 vulnerabilities is 6.4.

External reference: View CWE-532 on MITRE CWE →

Monitor CWE-532 Vulnerabilities

Get alerted when new CWE-532 CVEs affect your infrastructure.

Start Monitoring Free