Vulnerabilities (CVE)

Filtered by CWE-532
Total 1233 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-62211 1 Openclaw 1 Openclaw 2026-07-29 N/A 5.0 MEDIUM
OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that should remain within trusted boundaries. Attackers can exploit misconfigured input paths or feature accessibility to expose sensitive credentials and data through the export mechanism.
CVE-2026-64800 1 Jetbrains 1 Goland 2026-07-28 N/A 3.5 LOW
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
CVE-2026-65589 1 N8n 1 N8n 2026-07-27 N/A 6.5 MEDIUM
n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the database and can be exported.
CVE-2026-32982 1 Openclaw 1 Openclaw 2026-07-25 N/A 7.5 HIGH
OpenClaw before 2026.3.13 contains an information disclosure vulnerability in the fetchRemoteMedia function that exposes Telegram bot tokens in error messages. When media downloads fail, the original Telegram file URLs containing bot tokens are embedded in MediaFetchError strings and leaked to logs and error surfaces.
CVE-2019-25683 1 Filezilla-project 1 Filezilla Client 2026-07-24 N/A 6.2 MEDIUM
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in the search directory field and initiating a local search operation.
CVE-2026-35185 1 Psu 1 Haxiam 2026-07-24 N/A 7.5 HIGH
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is publicly accessible and exposes sensitive information including authentication tokens (user_token), user activity, client IP addresses, and server configuration details. This allows any unauthenticated user to monitor real-time user interactions and gather internal infrastructure information. This vulnerability is fixed in 25.0.0.
CVE-2026-4788 1 Ibm 1 Tivoli Netcool\/impact 2026-07-24 N/A 8.4 HIGH
IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores sensitive information in log files that could be read by a local user.
CVE-2026-4819 1 Search-guard 1 Flx 2026-07-24 N/A 4.9 MEDIUM
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
CVE-2026-28261 1 Dell 2 Elastic Cloud Storage, Objectscale 2026-07-24 N/A 7.8 HIGH
Dell Elastic Cloud Storage, version 3.8.1.7 and prior, and Dell ObjectScale, versions prior to 4.1.0.3 and version 4.2.0.0, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to secret exposure. The attacker may be able to use the exposed secret to access the vulnerable system with privileges of the compromised account.
CVE-2025-13755 1 Ibm 1 Db2 2026-07-24 N/A 5.5 MEDIUM
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes DB2 Connect Server) stores potentially sensitive information in log files that could be read by a local user.
CVE-2021-21508 2026-07-23 N/A 6.7 MEDIUM
Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
CVE-2026-8671 3 Avantra, Linux, Microsoft 3 Avantra, Linux Kernel, Windows 2026-07-23 N/A 7.5 HIGH
Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure. This issue affects Avantra: before 25.3.0.
CVE-2026-44052 2026-07-23 N/A 7.5 HIGH
Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.
CVE-2026-20239 1 Splunk 2 Splunk, Splunk Cloud Platform 2026-07-23 N/A 7.5 HIGH
In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the `_internal` index could view session cookies and response bodies that contain sensitive data.
CVE-2026-9751 1 Mongodb 1 Mongodb 2026-07-23 N/A 5.5 MEDIUM
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
CVE-2026-0267 1 Paloaltonetworks 1 Globalprotect 2026-07-23 N/A 5.5 MEDIUM
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app configuration would not normally permit them to do so.
CVE-2026-9735 1 Mongodb 1 Mongodb 2026-07-23 N/A 5.5 MEDIUM
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parameters are written to the log without redaction.
CVE-2026-45581 2026-07-23 N/A 5.5 MEDIUM
fabric-chaincode-java is a Java based implementation of Hyperledger Fabric chaincode shim APIs. From version 2.3.1 to before version 2.5.10, when chaincode is deployed in chaincode-as-a-service mode with TLS enabled, the chaincode server INFO level logging includes the TLS private key password in plaintext. An attacker with access to the chaincode server logs could recover the TLS private key password. If the attacker can also obtain the TLS private key, they could impersonate the chaincode server. This issue has been patched in version 2.5.10.
CVE-2026-50205 1 Acer 2 Connect M6e 5g, Connect M6e 5g Firmware 2026-07-22 N/A 8.2 HIGH
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
CVE-2026-45679 1 Opentelemetry 1 Ebpf Instrumentation 2026-07-22 N/A 6.5 MEDIUM
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redis error replies can contain attacker-controlled or sensitive values, this behavior can exfiltrate tokens, PII, or other confidential input into telemetry backends and inject untrusted text into downstream analysis systems. This issue has been patched in version 0.9.0.