Skip to main content

Threats Tagged 'cwe-778'

View all threats tagged with 'cwe-778'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-778

Threats Tagged 'cwe-778'

Click on any threat for detailed analysis and mitigation recommendations

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

Join the discussion

Bulletin ID: 2026-006-AWS Scope: AWS Content Type: Informational Publication Date: 2026/03/03 10:15 AM PST Description: Amazon RDS/Aurora is a managed relational database service. We identified CVE-2026-3494. In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (‐‐) or hash (#) style comments, the statement is not logged. Impacted versions: - MariaDB Server (10.6.24 and prior, 10.11.15 and prior, 11.4.9 and prior, and 11.8.5 and prior) - Amazon Aurora MySQL (2.12.5 and prior, 3.01.0 to 3.04.5, 3.05.1 to 3.10.2, and 3.11.0) - Amazon RDS for MySQL (5.7.44-RDS.20251212 and prior, 8.0.11 to 8.0.44, and 8.4.3 to 8.4.7) - Amazon RDS for MariaDB (10.6.24 and prior, 10.11.4 to 10.11.15, 11.4.3 to 11.4.9, and 11.8.3 to 11.8.5) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion

CVE-2025-62307 is a medium severity vulnerability in HCL IntelliOps Event Management (IEM) version 1.4.0 caused by insufficient logging. This weakness reduces the ability to detect attacks and weakens accountability by obscuring privilege probing activities. The vulnerability does not allow direct compromise of confidentiality or availability but impacts integrity and detection capabilities.

Join the discussion

CVE-2026-41709 is a low-severity vulnerability in VMware Cloud Foundation involving insufficient logging. A malicious administrator could perform certain operations without those actions being recorded in logs. This issue affects multiple versions of VMware Cloud Foundation, including 5.x, 9.0.x.x, and 9.1.x.x. No official patch or remediation guidance has been published yet, and there are no known exploits in the wild.

Join the discussion

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted `approve-recovery` API request.

Join the discussion

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.

Join the discussion

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This issue affects : * Devolutions Server 2026.1.6.0 through 2026.1.16.0 * Devolutions Server 2025.3.20.0 and earlier

Join the discussion

Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.

Join the discussion

In Juju from version 3.0.0 through 3.6.18, the authorization of the "secret-set" tool is not performed correctly, which allows a grantee to update the secret content, and can lead to reading or updating other secrets. When the "secret-set" tool logs an error in an exploitation attempt, the secret is still updated contrary to expectations, and the new value is visible to both the owner and the grantee.

Join the discussion

CVE-2026-25598 is a medium-severity vulnerability in the step-security Harden-Runner GitHub Action prior to version 2.14.2. It allows outbound network connections made via certain socket system calls (sendto, sendmsg, sendmmsg) to evade audit logging when egress-policy is set to audit. This insufficient logging weakness (CWE-778) can undermine the visibility of potentially malicious outbound traffic in CI/CD environments using Harden-Runner. The vulnerability does not require authentication or user interaction and has a CVSS score of 6.3. It is fixed in version 2.14.2.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: cwe-778
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses