When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.
Volume of CVEs assigned to CWE-778 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48967CRITICAL The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with acce | Nov 14, 2024 | 10.0 | 30 | NO | NO |
CVE-2026-32693HIGH In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead | Mar 18, 2026 | 8.8 | 29 | NO | NO |
CVE-2025-52644HIGH HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user a | Mar 16, 2026 | 8.2 | 25 | NO | NO |
CVE-2022-30305HIGH An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4. | Dec 6, 2022 | 7.5 | 25 | NO | NO |
CVE-2026-22279HIGH Dell PowerScale OneFS, versions prior 9.13.0.0, contains an insufficient logging vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulner | Jan 22, 2026 | 7.5 | 24 | NO | NO |
CVE-2023-1995HIGH Insufficient Logging vulnerability in Hitachi HiRDB Server, HiRDB Server With Addtional Function, HiRDB Structured Data Access Facility.This issue affects HiRDB Server: before 09-6 | Aug 29, 2023 | 7.5 | 23 | NO | NO |
CVE-2026-3494MEDIUM In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an | Mar 3, 2026 | 4.3 | 22 | NO | NO |
CVE-2019-19277MEDIUM A vulnerability has been identified in SIPORT MP (All versions < 3.1.4). Vulnerable versions of the device allow the creation of special accounts ("service users") with administrat | Mar 10, 2020 | 6.5 | 22 | NO | NO |
CVE-2026-25598MEDIUM Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub | Feb 9, 2026 | 5.3 | 21 | NO | NO |
CVE-2021-43419HIGH An Information Disclosure vulnerability exists in Opay Mobile application 1.5.1.26 and maybe be higher in the logcat app. | Nov 7, 2023 | 7.5 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.