Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-532

MITRE ↗

CWE-532

54
CRITICAL
255
HIGH
707
MEDIUM
143
LOW
1,194 CVEs · Page 5/24
7.5
CVE-2025-54376

Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v

7.5
CVE-2025-34183

Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows u

7.5
CVE-2025-62513

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe

7.5
CVE-2025-11504

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9

7.5
CVE-2025-62232

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f

7.5
CVE-2025-13743

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serializatio

7.5
CVE-2025-14437

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,

7.4
CVE-2025-41690

A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)

7.2
CVE-2025-6624

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through

7.1
CVE-2025-20231

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk S

7.1
CVE-2025-36573

Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul

6.8
CVE-2025-25002

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose inform

6.8
CVE-2025-7371

Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vu

6.6
CVE-2024-57957

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vul

6.6
CVE-2024-47570

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 throug

6.5
CVE-2024-12226

In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s

6.5
CVE-2025-1296

Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token a

6.5
CVE-2024-40585

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2

6.5
CVE-2025-25013

Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as AP

6.5
CVE-2025-30677

Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connecto

6.5
CVE-2025-27391

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker

6.5
CVE-2025-48493

The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, t

6.5
CVE-2024-9453

A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially c

6.5
CVE-2025-5464

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe

6.5
CVE-2025-8663

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know

6.5
CVE-2025-7445

Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.

6.5
CVE-2025-11446

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know

6.5
CVE-2025-64650

IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.

6.4
CVE-2025-1979

Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the r

6.3
CVE-2025-24389

Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log

6.3
CVE-2025-54319

An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized acces

6.2
CVE-2024-45091

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensi

6.2
CVE-2025-48955

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers

6.2
CVE-2025-49009

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers

6.2
CVE-2025-36050

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be

6.2
CVE-2025-59258

Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker

6.0
CVE-2025-2002

CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP s

6.0
CVE-2025-66910

Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authe

5.9
CVE-2025-24651

Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-du

5.9
CVE-2025-57813

traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists wh

5.9
CVE-2025-36133

IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 th

5.7
CVE-2025-37727

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco

5.6
CVE-2025-68919

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when

5.5
CVE-2024-40679

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulner

5.5
CVE-2025-21316

Windows Kernel Memory Information Disclosure Vulnerability

5.5
CVE-2025-21317

Windows Kernel Memory Information Disclosure Vulnerability

5.5
CVE-2025-21318

Windows Kernel Memory Information Disclosure Vulnerability

5.5
CVE-2025-21319

Windows Kernel Memory Information Disclosure Vulnerability

5.5
CVE-2025-21320

Windows Kernel Memory Information Disclosure Vulnerability

5.5
CVE-2025-21321

Windows Kernel Memory Information Disclosure Vulnerability

Frequently Asked Questions

What is CWE-532?

CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-532?

There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.

How can I protect against CWE-532 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.

Detect CWE-532 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.

Get Started