The product logs too much information, making log files hard to process and possibly hindering recovery efforts or forensic analysis after an attack.
Volume of CVEs assigned to CWE-779 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-36072CRITICAL Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector an | Jun 27, 2024 | 9.8 | 31 | NO | NO |
CVE-2026-20210MEDIUM A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configur | May 14, 2026 | 5.4 | 27 | NO | NO |
CVE-2026-20209MEDIUM A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their p | May 14, 2026 | 5.4 | 27 | NO | NO |
CVE-2025-8696HIGH If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk use problems for the system running the Stork server.
This issue affects Stork | Sep 10, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-51397MEDIUM A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a cr | Jul 21, 2025 | 5.4 | 24 | NO | YES |
CVE-2022-31004HIGH CVEProject/cve-services is an open source project used to operate the CVE services API. A conditional in 'data.js' has potential for production secrets to be written to disk. The a | Jun 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2026-28718HIGH Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | Mar 6, 2026 | 7.5 | 22 | NO | NO |
CVE-2024-55628HIGH Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead | Jan 6, 2025 | 7.5 | 22 | NO | NO |
CVE-2024-36416HIGH SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API example with no log rotation allows | Jun 10, 2024 | 7.5 | 22 | NO | NO |
CVE-2025-69230MEDIUM AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the c | Jan 6, 2026 | 5.3 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.