The hardware does not fully clear security-sensitive values, such as keys and intermediate values in cryptographic operations, when debug mode is entered.
Volume of CVEs assigned to CWE-1258 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15480CRITICAL In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Lau | Apr 9, 2026 | 9.1 | 34 | NO | NO |
CVE-2025-14551HIGH In Ubuntu, Subiquity version 24.04.4 could leak sensitive user credentials during crash reporting. Upon installation failure, if a user submitted a bug report to Launchpad, Subiqui | Apr 9, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-52696HIGH Unauthenticated Sensitive Data Exposure in JetBlog <= 2.4.8 versions. | Jun 17, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-32257MEDIUM Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability in 1clickmigration 1 Click WordPress Migration 1-click-migration allows Retrieve Embedded | Apr 4, 2025 | 5.3 | 26 | NO | YES |
CVE-2022-39292HIGH Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. | Oct 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-31162HIGH Slack Morphism is an async client library for Rust. Prior to 0.41.0, it was possible for Slack OAuth client information to leak in application debug logs. Stricter and more secure | Jul 22, 2022 | 7.5 | 23 | NO | NO |
CVE-2024-36913HIGH In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails
In CoCo VMs it is possible for the untrusted ho | May 30, 2024 | 8.1 | 22 | NO | NO |
CVE-2024-36912HIGH In the Linux kernel, the following vulnerability has been resolved:
Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl
In CoCo VMs it is possible for the untrusted host to | May 30, 2024 | 8.1 | 22 | NO | NO |
CVE-2023-48308MEDIUM Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar ap | Dec 22, 2023 | 6.5 | 20 | NO | NO |
CVE-2025-26482MEDIUM Dell PowerEdge Server BIOS and Dell iDRAC9, all versions, contains an Information Disclosure vulnerability. A high privileged attacker with remote access could potentially exploit | Sep 25, 2025 | 4.9 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.