VYPR

CWE-778

Insufficient Logging

BaseDraftLikelihood: Medium

Description

When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (27)

page 2 of 2
  • CVE-2026-32803LowMay 8, 2026
    risk 0.21cvss 3.3epss 0.00

    Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through 9.10.1.5 and 9.11.0.0 through 9.12.0.1 contains an Insufficient Logging vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability,…

  • CVE-2024-24901LowMar 4, 2024
    risk 0.20cvss 3.0epss 0.00

    Dell PowerScale OneFS 8.2.x through 9.6.0.x contain an insufficient logging vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, causing audit messages lost and not recorded for a specific time period.

  • CVE-2026-9247LowMay 22, 2026
    risk 0.16cvss 2.4epss 0.00

    Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request. This issue affects : * Devolutions…

  • CVE-2026-41709LowJul 30, 2026
    risk 0.00cvss 2.7epss 0.00

    VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

  • CVE-2025-66552MedDec 5, 2025
    risk 0.00cvss 4.3epss 0.00

    Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This…

  • CVE-2022-31120LowAug 4, 2022
    risk 0.00cvss 2.1epss 0.01

    Nextcloud server is an open source personal cloud solution. The audit log is used to get a full trail of the actions which has been incompletely populated. In affected versions federated share events were not properly logged which would allow brute force attacks to go unnoticed.…

  • CVE-2021-32680LowJul 12, 2021
    risk 0.00cvss 3.3epss 0.00

    Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged.…