Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,163 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 145 Low, 0 Unrated.

CVE-2026-22778

Published Feb 2, 2026

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an e…

CVSS 9.8 · Critical
evidence mentions
15
Buzz score
40.7
Vendor/product tagsBeta · best-effort

CVE-2026-25211

Published Jan 30, 2026

Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.

CVSS 3.2 · Low
evidence mentions
2
Buzz score
16.0

CVE-2026-0936

Published Jan 29, 2026

An Insertion of Sensitive Information into Log File vulnerability in B&R PVI client versions prior to 6.5 may be abused by an authenticated local attacker to gather credential inf…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-13925

Published Jan 20, 2026

IBM Aspera Console 3.4.7 stores potentially sensitive information in log files that could be read by a local privileged user.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-59355

Published Jan 19, 2026

A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter string in the log via logger.er…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-0519

Published Jan 17, 2026

In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to thos…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-43508

Published Jan 16, 2026

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2026-22782

Published Jan 16, 2026

RustFS is a distributed object storage system built in Rust. From >= 1.0.0-alpha.1 to 1.0.0-alpha.79, invalid RPC signatures cause the server to log the shared HMAC secret (and ex…

CVSS 2.9 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-68675

Published Jan 16, 2026

In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authentication information. These f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2026-23493

Published Jan 15, 2026

Pimcore is an Open Source Data & Experience Management Platform. Prior to 12.3.1 and 11.5.14, the http_error_log file stores the $_COOKIE and $_SERVER variables, which means sensi…

CVSS 8.6 · High
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-22798

Published Jan 12, 2026

hermes is an implementation of the HERMES workflow to automatize software publication with rich metadata. From 0.8.1 to before 0.9.1, hermes subcommands take arbitrary options und…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-68919

Published Dec 24, 2025

Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when collected maintenance data is accessible by a principal/aut…

CVSS 5.6 · Medium

CVE-2025-66910

Published Dec 19, 2025

Turms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. The BaseAdminService class caches adminis…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14437

Published Dec 18, 2025

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This make…

CVSS 7.5 · High

CVE-2025-43475

Published Dec 17, 2025

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.2 and iPadOS 26.2. An app may be able to access user-sensitive data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-13321

Published Dec 17, 2025

Mattermost Desktop App versions <6.0.0 fail to sanitize sensitive information from Mattermost logs and clear data on server deletion which allows an attacker with access to the us…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-14432

Published Dec 16, 2025

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log fi…

CVSS 8.1 · High

CVE-2025-43517

Published Dec 12, 2025

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2. An app may…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-13743

Published Dec 9, 2025

Docker Desktop diagnostics bundles were found to include expired Hub PATs in log output due to error object serialization. This poses a risk of leaking sensitive information in ex…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36876

Published Dec 5, 2025

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webs…

CVSS 8.7 · High

CVE-2025-12996

Published Dec 4, 2025

Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext passwords from errors logged under certain circumstances. T…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 1,163 CVEsPage 6 of 47