Skip to main content

CWE archive

CWE-532 CVEs

Programmatic archive

1,163 CVEs tagged with CWE-53256 Critical, 259 High, 703 Medium, 145 Low, 0 Unrated.

CVE-2025-14010

Published Dec 4, 2025

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifically plaintext passwords, via v…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66411

Published Dec 3, 2025

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28.4, Workspace Agent manifests containing sensitive values w…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-13611

Published Nov 26, 2025

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to c…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-20373

Published Nov 26, 2025

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the addition of new “Data Security Acco…

CVSS 2.7 · Low

CVE-2025-11446

Published Nov 19, 2025

Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: f…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54971

Published Nov 18, 2025

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all vers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11008

Published Nov 4, 2025

The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.3.1 via the log file. This makes it possible for unauth…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2025-43426

Published Nov 4, 2025

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62232

Published Oct 31, 2025

Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This cr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58189

Published Oct 29, 2025

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58269

Published Oct 29, 2025

A vulnerability has been identified in Rancher Manager, where sensitive information, including secret data, cluster import URLs, and registration tokens, is exposed to any entit…

CVSS 4.3 · Medium

CVE-2025-11248

Published Oct 27, 2025

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could…

CVSS 3.2 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11504

Published Oct 24, 2025

The Quickcreator – AI Blog Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 0.0.9 to 0.1.17 through the /wp-content/plugins/quickcreator/dup…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2025-62705

Published Oct 22, 2025

OpenBao is an open source identity-based secrets management system. Prior to version 2.4.2, OpenBao's audit log did not appropriately redact fields when relevant subsystems sent […

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62513

Published Oct 22, 2025

OpenBao is an open source identity-based secrets management system. In versions 2.2.0 to 2.4.1, OpenBao's audit log experienced a regression wherein raw HTTP bodies used by few en…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46752

Published Oct 16, 2025

A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the en…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10486

Published Oct 15, 2025

The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.8 through publicly exposed log files. This makes…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
32.6
Showing 151-175 of 1,163 CVEsPage 7 of 47