Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, Hoverfly’s admin WebSocket endpoint /api/v
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows u
OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log expe
The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9
Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and f
Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serializatio
The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,
A low-privileged attacker in bluetooth range may be able to access the password of a higher-privilege user (Maintenance)
Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk S
Dell Smart Dock Firmware, versions prior to 01.00.08.01, contain an Insertion of Sensitive Information into Log File vul
Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose inform
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vu
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vul
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 throug
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes s
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token a
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2
Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as AP
Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connecto
Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker
The Yii 2 Redis extension provides the redis key-value store support for the Yii framework 2.0. On failing connection, t
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially c
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authe
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know
Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files.
Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the r
Certain errors of the upstream libraries will insert sensitive information in the OTRS or ((OTRS)) Community Edition log
An issue was discovered in Westermo WeOS 5 (5.24 through 5.24.4). A threat actor potentially can gain unauthorized acces
IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.24, 7.1 through 7.1.2.10, and 7.2 through 7.2.3.13 stores potentially sensi
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in vers
IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker
CWE-532: Insertion of Sensitive Information into Log Files vulnerability exists that could cause the disclosure of FTP s
Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authe
Insertion of Sensitive Information into Log File vulnerability in WebToffee WordPress Backup & Migration wp-migration-du
traQ is a messenger application built for Digital Creators Club traP. Prior to version 3.25.0, a vulnerability exists wh
IBM App Connect Enterprise Certified Container CD: 9.2.0 through 11.6.0, 12.1.0 through 12.14.0, and 12.0 LTS: 12.0.0 th
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preco
Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulner
Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Windows Kernel Memory Information Disclosure Vulnerability
Frequently Asked Questions
What is CWE-532?
CWE-532 (CWE-532) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-532?
There are 1,485 CVE records associated with CWE-532 in our database. Of these, 54 are critical severity, 255 are high severity, and 707 are medium severity.
How can I protect against CWE-532 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-532 using AI-powered security agents.
Detect CWE-532 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-532 vulnerabilities across your infrastructure.
Get Started