The product writes sensitive information to a log file.
Volume of CVEs assigned to CWE-532 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
1,164 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1622MEDIUM A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information | Jun 27, 2019 | 5.3 | 79 | NO | YES |
CVE-2020-35234HIGH The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/ | Dec 14, 2020 | 7.5 | 77 | NO | YES |
CVE-2023-43261HIGH An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | Oct 4, 2023 | 7.5 | 72 | NO | YES |
CVE-2024-20440HIGH A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information.
This vulnerability is due to excessive verbosit | Sep 4, 2024 | 7.5 | 65 | NO | YES |
CVE-2025-24984MEDIUM Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack. | Mar 11, 2025 | 4.6 | 55 | YES | NO |
CVE-2023-21492MEDIUM Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | May 4, 2023 | 4.4 | 55 | YES | NO |
CVE-2026-22778CRITICAL vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an er | Feb 2, 2026 | 9.8 | 53 | NO | YES |
CVE-2018-8719MEDIUM An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these fi | Apr 4, 2018 | 5.3 | 45 | NO | YES |
CVE-2025-14437HIGH The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes | Dec 18, 2025 | 7.5 | 42 | NO | YES |
CVE-2026-49200CRITICAL The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leadin | May 29, 2026 | 9.8 | 41 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.