Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2025-44203

Published Jun 20, 2025

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49128

Published Jun 6, 2025

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.1…

CVSS 4.0 · Medium

CVE-2025-25025

Published May 28, 2025

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information coul…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40653

Published May 26, 2025

User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine w…

CVSS 6.9 · Medium

CVE-2025-41441

Published May 26, 2025

Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerabi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46746

Published May 12, 2025

An administrator could discover another account's credentials.

CVSS 5.8 · Medium

CVE-2025-4166

Published May 2, 2025

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0049

Published Apr 28, 2025

When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow…

CVSS 3.5 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-46575

Published Apr 27, 2025

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20150

Published Apr 16, 2025

A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11129

Published Apr 10, 2025

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0279

Published Apr 3, 2025

HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error co…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-47639

Published Apr 3, 2025

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON…

CVSS 5.3 · Medium

CVE-2025-31141

Published Mar 27, 2025

In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-12380

Published Mar 13, 2025

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 bef…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2239

Published Mar 12, 2025

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation Fi…

CVSS 5.3 · Medium

CVE-2025-23185

Published Mar 11, 2025

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in st…

CVSS 4.1 · Medium

CVE-2025-20002

Published Mar 5, 2025

After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure

CVSS 6.9 · Medium
Showing 126-150 of 574 CVEsPage 6 of 23