CWE-778 不充分的日志记录 类弱点 21 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-778 属于日志记录不足漏洞,指系统在发生安全关键事件时未记录或遗漏关键细节。攻击者常利用此缺陷隐藏恶意行为,如暴力破解登录,从而逃避检测并阻碍事后取证分析。开发者应确保记录所有安全事件的关键上下文,实施集中式日志管理并定期审查日志完整性,以保障可追溯性与威胁检测能力。
<system.serviceModel> <behaviors> <serviceBehaviors> <behavior name="NewBehavior"> <serviceSecurityAudit auditLogLocation="Default" suppressAuditFailure="false" serviceAuthorizationAuditLevel="None" messageAuthenticationAuditLevel="None" /> ... </system.serviceModel><system.serviceModel> <behaviors> <serviceBehaviors> <behavior name="NewBehavior"> <serviceSecurityAudit auditLogLocation="Default" suppressAuditFailure="false" serviceAuthorizationAuditLevel="SuccessAndFailure" messageAuthenticationAuditLevel="SuccessAndFailure" /> ... </system.serviceModel>if LoginUser(){ // Login successful RunProgram(); } else { // Login unsuccessful LoginRetry(); }if LoginUser(){ // Login successful log.warn("Login by user successful."); RunProgram(); } else { // Login unsuccessful log.warn("Login attempt by user failed, trying again."); LoginRetry(); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-32803 | Dell PowerScale OneFS 多个版本日志不足漏洞 — PowerScale OneFS | 3.3 | Low | 2026-05-08 |
| CVE-2026-3494 | MCP MariaDB Server 安全漏洞 — MariaDB Server | 4.3 | Medium | 2026-03-03 |
| CVE-2026-25598 | Harden-Runner 安全漏洞 — harden-runner | 5.3AI | MediumAI | 2026-02-09 |
| CVE-2026-22279 | Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS | 4.3 | Medium | 2026-01-22 |
| CVE-2025-66552 | Nextcloud Server 安全漏洞 — security-advisories | 4.3 | Medium | 2025-12-05 |
| CVE-2025-53498 | Wikimedia Mediawiki - AbuseFilter Extension 安全漏洞 — Mediawiki - AbuseFilter Extension | 5.3AI | MediumAI | 2025-07-07 |
| CVE-2025-32967 | OpenEMR 安全漏洞 — openemr | 5.4 | Medium | 2025-05-23 |
| CVE-2025-2562 | Devolutions Remote Desktop Manager 安全漏洞 — Remote Desktop Manager | 8.8AI | HighAI | 2025-03-26 |
| CVE-2024-10863 | OpenText Secure Content Manager 安全漏洞 — Secure Content Manager | 5.3 | - | 2024-11-22 |
| CVE-2024-48967 | Baxter Life2000 安全漏洞 — Life2000 Ventilation System | 10.0 | Critical | 2024-11-14 |
| CVE-2024-2291 | Progress MOVEit Transfer 安全漏洞 — MOVEit Transfer | 4.3 | Medium | 2024-03-20 |
| CVE-2024-24901 | Dell PowerScale OneFS 安全漏洞 — PowerScale OneFS | 3.0 | Low | 2024-03-04 |
| CVE-2023-1995 | Hitachi HiRDB Server 安全漏洞 — HiRDB Server | 5.3 | Medium | 2023-08-29 |
| CVE-2022-30305 | Fortinet FortiSandbox 安全漏洞 — FortiSandbox | 3.6 | Low | 2022-12-06 |
| CVE-2022-31120 | Nextcloud 安全漏洞 — security-advisories | 2.1 | Low | 2022-08-04 |
| CVE-2022-25783 | Secomea GateManager 安全漏洞 — GateManager | 4.3 | Medium | 2022-05-04 |
| CVE-2021-33689 | SAP NetWeaver AS 安全漏洞 — SAP NetWeaver AS JAVA (Administrator applications) | 4.3 | - | 2021-07-14 |
| CVE-2021-32680 | Nextcloud 安全漏洞 — security-advisories | 3.3 | Low | 2021-07-12 |
| CVE-2019-19277 | Siemens SIPORT MP 安全漏洞 — SIPORT MP | 6.5 | - | 2020-03-10 |
| CVE-2019-19295 | Siemens SiNVR 3 Central Control Server和SiNVR 3 Video Server 安全漏洞 — Control Center Server (CCS) | 4.3 | Medium | 2020-03-10 |
| CVE-2019-7613 | Elasticsearch Winlogbeat 输入验证错误漏洞 — Logstash | 5.3 | - | 2019-03-25 |
CWE-778(不充分的日志记录) 是常见的弱点类别,本平台收录该类弱点关联的 21 条 CVE 漏洞。