Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,163 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 145 Low, 0 Unrated.

CVE-2018-8719

Published Apr 4, 2018

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3817

Published Mar 30, 2018

When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0898

Published Mar 29, 2018

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the sys…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1350

Published Mar 26, 2018

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system enumeration.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1349

Published Mar 26, 2018

The NetIQ Identity Manager driver log file, in versions prior to 4.7, provides details that could aid in system or configuration enumeration.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-1000123

Published Mar 13, 2018

Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000089

Published Mar 13, 2018

Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7204

Published Mar 7, 2018

inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt. If a user edits the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7433

Published Mar 2, 2018

The iThemes Security plugin before 6.9.1 for WordPress does not properly perform data escaping for the logs page.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9278

Published Mar 2, 2018

The NetIQ Identity Manager Oracle EBS driver before 4.0.2.0 sent EBS logs containing the driver authentication password, potentially disclosing this to attackers able to read the…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-7434

Published Mar 2, 2018

In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-2372

Published Feb 14, 2018

A plain keystore password is written to a system log file in SAP HANA Extended Application Services, 1.0, which could endanger confidentiality of SSL communication.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-1000060

Published Feb 9, 2018

Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5693

Published Jan 14, 2018

The LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading /var/log/magicspam/mslog.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-1727

Published Jan 4, 2018

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6139

Published Dec 21, 2017

In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file c…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8001

Published Nov 28, 2017

An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials of the ScaleIO MDM user who executed the script in clear t…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16946

Published Nov 25, 2017

The admin_edit function in app/Controller/UsersController.php in MISP 2.4.82 mishandles the enable_password field, which allows admins to discover a hashed password by reading the…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000171

Published Nov 3, 2017

Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,101-1,125 of 1,163 CVEsPage 45 of 47