The CVEProject/cve-services is an open source project used to operate the CVE services api. In versions up to and includ
IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user wi
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) charact
TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29,
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages
A cleartext storage of sensitive information exists in Rocket.Chat <v4.6.4 due to Oauth token being leaked in plaintext
A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to sensitive information exposure by passing API ke
IBM MQ Internet Pass-Thru 2.1, 9.2 LTS and 9.2 CD stores potentially sensitive information in trace files that could be
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text wit
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could all
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retriev
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorr
Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for
An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This coul
A vulnerability in the audit log of Cisco DNA Center could allow an authenticated, local attacker to view sensitive info
In __show_regs of process.c, there is a possible leak of kernel memory and addresses due to log information disclosure.
In JetBrains TeamCity before 2022.04 leak of secrets in TeamCity agent logs was possible
In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perf
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3.
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). A customized HTTP POST reques
VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo
Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may log request headers in some cases of invalid HTTP requests.
A vulnerability has been identified in Micro Focus GroupWise Web in versions prior to 18.4.2. The GW Web component makes
The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that c
Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing tha
Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying l
Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially be
In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an u
HCL Launch may store certain data for recurring activities in a plain text format.
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Port
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthori
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to
Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulne
An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows tha
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. Th
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure. This could lead
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local a
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local atta
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to acce
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows l
NextAuth.js is a complete open source authentication solution for Next.js applications. An information disclosure vulner
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started