Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

588 CVEs tagged with CWE-20927 Critical, 75 High, 403 Medium, 82 Low, 1 Unrated.

CVE-2021-22169

Published Mar 24, 2021

An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22193

Published Mar 24, 2021

An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-20402

Published Feb 11, 2021

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the brow…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4628

Published Jan 27, 2021

IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the brow…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15219

Published Jan 13, 2021

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2505

Published Dec 24, 2020

If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-4846

Published Dec 17, 2020

IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-35177

Published Dec 17, 2020

HashiCorp Vault and Vault Enterprise 1.4.1 and newer allowed the enumeration of users via the LDAP auth method. Fixed in 1.5.6 and 1.6.1.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-16128

Published Dec 9, 2020

The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-25640

Published Nov 24, 2020

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4483

Published Nov 6, 2020

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4584

Published Oct 30, 2020

IBM i2 iBase 8.9.13 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 588 CVEsPage 19 of 24