Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-532 (通过日志文件的信息暴露) — Vulnerability Class 598

598 vulnerabilities classified as CWE-532 (通过日志文件的信息暴露). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-40945 Oxia: Bearer token exposed in debug log messages on authentication failure — oxia 7.5AIHighAI2026-04-21
CVE-2026-23775 Dell PowerProtect Data Domain(Dell PowerProtect DD) 安全漏洞 — PowerProtect Data Domain appliances 7.6 High2026-04-17
CVE-2026-34164 Valtimo: Sensitive data exposure through inbox message logging in InboxHandlingService — valtimo 4.9 Medium2026-04-16
CVE-2025-43937 Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS 6.6 Medium2026-04-16
CVE-2026-31987 Apache Airflow: JWT token appearing in logs — Apache Airflow 6.5AIMediumAI2026-04-16
CVE-2026-20205 Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app — Splunk MCP Server 7.2 High2026-04-15
CVE-2026-40091 SpiceDB: SPICEDB_DATASTORE_CONN_URI is leaked on startup logs — spicedb 6.0 Medium2026-04-14
CVE-2026-0207 Sensitive Information Logging Vulnerability in FlashBlade — FlashBlade 7.5 -2026-04-14
CVE-2026-32218 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 21H2 5.5 Medium2026-04-14
CVE-2026-32217 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 1607 5.5 Medium2026-04-14
CVE-2026-32215 Windows Kernel Information Disclosure Vulnerability — Windows 10 Version 1809 5.5 Medium2026-04-14
CVE-2026-2401 Schneider Electric PowerChute Serial Shutdown 日志信息泄露漏洞 — PowerChute™ Serial Shutdown 6.5 -2026-04-14
CVE-2025-66236 Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI — Apache Airflow 9.6 -2026-04-13
CVE-2026-34487 Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token — Apache Tomcat 7.5AIHighAI2026-04-09
CVE-2026-4901 Insertion of Sesitive Information into Log File in Hydrosystem Control System — Control System 5.5AIMediumAI2026-04-09
CVE-2026-28261 Dell ObjectScale和Dell Elastic Cloud Storage 日志信息泄露漏洞 — Elastic Cloud Storage 7.8 High2026-04-08
CVE-2026-4788 Multiple Vulnerabilities affect IBM Tivoli Netcool Impact — Tivoli Netcool Impact 8.4 High2026-04-08
CVE-2026-27315 Apache Cassandra: cqlsh history sensitive information leak — Apache Cassandra 6.5AIMediumAI2026-04-07
CVE-2019-25683 FileZilla 3.40.0 Denial of Service via Local Search — FileZilla 6.2 Medium2026-04-05
CVE-2026-4819 Search Guard audit logs can contain under certain conditions user credentials — Search Guard FLX 4.9 Medium2026-03-31
CVE-2026-32982 OpenClaw < 2026.3.13 - Telegram Bot Token Exposure in Media Fetch Error Logs — OpenClaw 7.5 High2026-03-31
CVE-2026-4957 OpenBMB XAgent API Key function_handler.py FunctionHandler.handle_tool_call log file — XAgent 2.7 Low2026-03-27
CVE-2024-11604 Insertion of Sensitive Information into Log File — IDM Driver and Extensions 5.5 -2026-03-27
CVE-2025-36187 Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge — Knowledge Catalog Standard Cartridge 4.4 Medium2026-03-25
CVE-2026-32598 OneUptime: Password Reset Token Logged at INFO Level — oneuptime 8.1 -2026-03-12
CVE-2026-0520 Lenovo Filez 安全漏洞 — FileZ 2.8 Low2026-03-11
CVE-2026-20165 Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise — Splunk Enterprise 6.3 Medium2026-03-11
CVE-2026-21791 HCL Sametime for Android is affected by sensitive information disclosure — Sametime 3.3 Low2026-03-10
CVE-2026-29184 @backstage/plugin-scaffolder-backend: Potential Session Token Exfiltration via Log Redaction Bypass — backstage 2.0 Low2026-03-07
CVE-2026-24308 Apache ZooKeeper: Sensitive information disclosure in client configuration handling — Apache ZooKeeper 7.5 -2026-03-07

Vulnerabilities classified as CWE-532 (通过日志文件的信息暴露) represent 598 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.