Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

589 CVEs tagged with CWE-20927 Critical, 76 High, 403 Medium, 82 Low, 1 Unrated.

CVE-2025-20150

Published Apr 16, 2025

A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts. This vulnerability is due to the improper handling of…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-11129

Published Apr 10, 2025

An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. This allows attackers to perform targeted…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-32238

Published Apr 4, 2025

Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows R…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0279

Published Apr 3, 2025

HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error co…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-47639

Published Apr 3, 2025

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messages, that are not HTTP exceptions, are visible in the JSON…

CVSS 5.3 · Medium

CVE-2025-31141

Published Mar 27, 2025

In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-12380

Published Mar 13, 2025

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 bef…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2239

Published Mar 12, 2025

Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generation FireWall.This issue affects Hillstone Next Generation Fi…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-23185

Published Mar 11, 2025

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the application are revealed in exceptions thrown to the user and in st…

CVSS 4.1 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-20002

Published Mar 5, 2025

After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information disclosure

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-0941

Published Feb 26, 2025

MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available to unauthe…

CVSS 5.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-13537

Published Feb 21, 2025

The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. This is due the plugin containing a publicly accessible compo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13540

Published Feb 18, 2025

The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.5.1. This…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13539

Published Feb 12, 2025

The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1. This is due the /vendor/aura/payload-interface/phpunit.php…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 589 CVEsPage 7 of 24