Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-532

Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

1,164
Assigned CVEs
46th
Commonality Rank
6.0
Avg CVSS
0.2%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-532 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2001
24 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

1,164 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-1622MEDIUM
A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to retrieve sensitive information
Jun 27, 20195.379NOYES
CVE-2020-35234HIGH
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/
Dec 14, 20207.577NOYES
CVE-2023-43261HIGH
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
Oct 4, 20237.572NOYES
CVE-2024-20440HIGH
A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosit
Sep 4, 20247.565NOYES
CVE-2025-24984MEDIUM
Insertion of sensitive information into log file in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.
Mar 11, 20254.655YESNO
CVE-2023-21492MEDIUM
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
May 4, 20234.455YESNO
CVE-2026-22778CRITICAL
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an er
Feb 2, 20269.853NOYES
CVE-2018-8719MEDIUM
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these fi
Apr 4, 20185.345NOYES
CVE-2025-14437HIGH
The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes
Dec 18, 20257.542NOYES
CVE-2026-49200CRITICAL
The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file contains cleartext login credentials (for web and Telnet), leadin
May 29, 20269.841NONO
View all 1,164 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
14%
10%
4.0-4.9
31%
19%
5.0-5.9
17%
16%
6.0-6.9
20%
26%
7.0-7.9
11%
8.0-8.9
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
2 CVEs
0.2% of CVEs· 81st percentile
Metasploit
3 CVEs
0.3% of CVEs· 80th percentile
Nuclei
8 CVEs
0.7% of CVEs· 82nd percentile
ExploitDB
5 CVEs
0.4% of CVEs· 75th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products