$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-532 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-532

전체 목록

55건

CVE-2026-73457Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interfa…0.3%보통6.0
CVE-2026-85174SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-te…0.3%높음8.7
CVE-2026-63208Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph req…0.3%보통5.1
CVE-2026-88883Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images be…0.3%높음8.3
CVE-2026-87993The consul-template library is vulnerable to an information disclosure issue in its error handling path that m…0.3%높음7.7
CVE-2026-104055The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicate…0.3%보통5.3
CVE-2026-92237Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell U…0.3%보통6.5
CVE-2026-86501In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log0.3%낮음2.8
CVE-2026-81862Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTerad…0.3%보통6.5
CVE-2026-104872OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript a…0.2%보통5.8
CVE-2026-73442On affected platforms running Arista EOS with VRRP enabled, the peer device VRRP authentication credentials ar…0.2%낮음2.1
CVE-2025-46808An Insertion of Sensitive Information into Log File vulnerability in SUSE neuvector manager exposes sensitive …0.2%보통6.8
CVE-2025-71423Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the …0.2%높음8.5
CVE-2026-81870OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerP…0.2%낮음2.0
CVE-2026-85417Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords …0.2%보통6.4
CVE-2025-71425Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when…0.2%높음8.5
CVE-2026-92872Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the…0.2%보통5.3
CVE-2026-82716The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credential…0.2%보통5.1
CVE-2026-82372Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions b…0.2%높음8.5
CVE-2026-93982OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameter…0.2%보통4.8
CVE-2026-95815OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified l…0.2%높음7.2
CVE-2026-82723Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclo…0.1%낮음1.8
CVE-2026-14442An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials t…0.2%보통6.9
CVE-2026-49810Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Informatio…0.2%높음7.8
CVE-2026-78242Insertion of sensitive information into log file vulnerability in Apache APISIX. This vulnerability can cause …0.2%보통5.7
CVE-2026-92758If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect…0.2%보통5.7
CVE-2026-81320A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at deb…0.1%보통5.5
CVE-2026-16689IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.1%보통6.2
CVE-2026-19649IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.1%보통6.2
CVE-2026-82371Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables indi…0.1%높음8.5
CVE-2026-77285OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rende…0.1%낮음2.4
CVE-2026-55102hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API met…0.1%보통5.8
CVE-2026-66068RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LO…0.1%보통5.6
CVE-2026-94594Armatura One's message broker logs client connection credentials and the associated password in plain text dur…0.1%보통5.1
CVE-2026-94593Armatura One's backup and restore routine records the full database connection command, including the superuse…0.1%높음8.5
CVE-2026-14443Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permi…0.1%높음8.4
CVE-2026-78627The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property…0.1%높음7.3
CVE-2026-17442IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.1%보통5.1
CVE-2026-80124Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.5
CVE-2026-80056Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%보통5.5
CVE-2026-78631The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the defa…0.1%보통5.3
CVE-2026-80169Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%낮음3.3
CVE-2026-79966Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.1%낮음3.3
CVE-2026-73466On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear …0.1%보통6.0
CVE-2026-73465On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in…0.1%보통6.0
CVE-2026-73467On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured …0.1%보통6.0
CVE-2026-86597Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODB…0.1%보통6.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.