CWE-209: CWE-209
Yearly Trend
Top Affected Vendors
All CWE-209 CVEs (109)
Squid caching proxy versions before 7.2 fail to properly redact HTTP authentication credentials in error messages, allowing information disclosure. Th...
Oct 17, 2025CVE-2025-46658 is an information disclosure vulnerability in 4C Strategies ExonautWeb where verbose error messages expose sensitive system information...
Aug 5, 2025A verbose error handling issue in the GravityZone Update Server proxy service allows attackers to perform server-side request forgery (SSRF) attacks. ...
Jul 31, 2024CVE-2024-28285 is a fault injection vulnerability in Crypto++'s ElGamal decryption function that allows a co-resident attacker on the same system to e...
May 14, 2024This vulnerability in PHPJabbers Document Creator v1.0 allows attackers to enumerate valid user accounts through the password recovery feature. By obs...
Aug 28, 2023This vulnerability in PHP Jabbers Hotel Booking System v4.0 allows attackers to enumerate valid user accounts through password recovery functionality....
Aug 28, 2023This vulnerability in PHPJabbers Fundraising Script v1.0 allows attackers to enumerate valid user accounts through the password recovery feature. By o...
Aug 28, 2023This vulnerability in PHP Jabbers Car Rental Script v3.0 allows attackers to enumerate valid user accounts through the password recovery feature. By o...
Aug 28, 2023This vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to enumerate valid user accounts through the password recovery feature. B...
Aug 28, 2023Dell PowerScale OneFS versions 8.2.x through 9.3.0.x contain an error message that leaks sensitive information. This vulnerability allows administrato...
Jun 28, 2022This vulnerability in Dispatch's Basic Authentication Provider plugin exposes the JWT secret key in error messages when JWT token decoding fails. Atta...
Aug 17, 2023This vulnerability allows remote authenticated users to obtain sensitive information through error messages in Hitachi RAID Manager Storage Replicatio...
Sep 6, 2022This vulnerability exposes client certificate passwords in exception logs when SSL authentication fails in ClickHouse Java clients. Attackers who can ...
Jan 19, 2024phpMyFAQ versions before 4.0.0 expose database credentials in error messages when database connection fails. This allows attackers to obtain sensitive...
Dec 6, 2024VMware Aria Operations for Logs contains an information disclosure vulnerability where authenticated users with View Only Admin permissions can read c...
Jan 30, 2025This CVE describes an information disclosure vulnerability in HeyGarson software where error messages reveal sensitive information during fuzzing atta...
Jan 30, 2026This vulnerability in league/oauth2-server exposes cryptographic keys in error messages when keys are passed as strings without valid passphrases. Att...
Jul 6, 2023This CVE describes an information exposure vulnerability in Progress Software Corporation's Sitefinity CMS where error messages reveal sensitive syste...
Jan 7, 2025This vulnerability in openssh_key_parser allows attackers to expose sensitive key field values through error messages. Attackers can manipulate declar...
Jul 6, 2022This vulnerability in Combodo iTop allows non-admin users to access sensitive class/field values through error messages in the GroupBy Dashlet. It aff...
Jul 21, 2021This vulnerability in Kentico Xperience allows attackers to view detailed error messages containing sensitive stack trace information through Portal E...
Dec 18, 2025IBM Security Verify Governance Identity Manager 10.0.2 discloses sensitive technical error information to remote attackers. This information leakage v...
Aug 28, 2025An unauthenticated attacker can exploit verbose SQL error messages in HotelDruid 3.0.7 to extract administrator credentials (username, password hash, ...
Jun 20, 2025CodeIgniter4 versions before 4.4.3 display detailed error reports in production environments when errors or exceptions occur, potentially leaking sens...
Oct 31, 2023CVE-2023-37306 is an information disclosure vulnerability in MISP (Malware Information Sharing Platform) where improper handling of certificate file e...
Jun 30, 2023This vulnerability in Apache Airflow AWS Provider versions before 7.2.1 allows error messages to leak sensitive information. Attackers can exploit thi...
Feb 24, 2023This vulnerability in the Valinor PHP library allows attackers to extract sensitive information from error messages that should not be exposed. Attack...
Jul 11, 2022This vulnerability in NocoDB prior to version 0.91.7+ allows error messages to expose sensitive information. Attackers can exploit this to obtain inte...
Jun 13, 2022This vulnerability in Ruby on Rails Action Pack allows attackers to perform information disclosure or unintended method execution when using redirect_...
May 27, 2021IBM Security Identity Manager 7.0.2 returns detailed technical error messages to remote attackers, potentially exposing sensitive system information. ...
May 20, 2021IBM QRadar User Behavior Analytics versions 1.0.0 through 4.1.0 expose detailed technical error messages to remote attackers when errors occur. This i...
May 14, 2021This vulnerability in Xen's x86 APIC implementation allows a malicious guest VM to trigger a deadlock in the hypervisor by configuring error interrupt...
Sep 25, 2024This vulnerability in Apache Airflow allows authenticated users with DAG view permissions to potentially see sensitive information like secrets when a...
Feb 21, 2026A vulnerability in Brocade SANnav's update-reports-purge-settings.sh script logs the database password to system audit logs. This allows authenticated...
Feb 3, 2026This vulnerability allows external users to trigger a 500 error in LimeSurvey by sending malformed session cookies, which exposes sensitive internal s...
Nov 20, 2025This vulnerability allows remote attackers to obtain sensitive technical error information from IBM QRadar Suite and Cloud Pak for Security systems. A...
Aug 16, 2024IBM MQ Console versions 9.3 LTS and 9.3 CD expose detailed technical error messages to remote attackers, potentially revealing sensitive system inform...
Jun 28, 2024This vulnerability in GitLab EE allows attackers to perform targeted searches with sensitive keywords to obtain counts of issues containing those term...
Apr 10, 2025IBM MQ web console versions 9.2-9.4 can leak sensitive technical error information to remote attackers. This information disclosure vulnerability affe...
Dec 19, 2024Apache Hive and Spark expose correct cookie signatures during signature mismatch errors, potentially allowing attackers to forge valid signed cookies....
Dec 23, 2024OpenClaw session tools allowed broader session targeting than intended in shared-agent deployments, potentially exposing transcript content across pee...
Feb 20, 2026This Windows Kernel vulnerability allows authenticated local attackers to extract sensitive information through error messages. Attackers with valid c...
Jan 13, 2026A vulnerability in Altair Grid Engine versions before V2026.0.0 allows local attackers to extract password hashes for privileged accounts through erro...
Nov 11, 2025This vulnerability in the Windows USB Video Driver allows an authorized attacker to read sensitive information from error messages. It affects Windows...
Oct 14, 2025This vulnerability in Infinispan CLI exposes sensitive passwords in error messages when commands fail. Attackers could potentially capture passwords b...
Jun 26, 2025This vulnerability in Firefox and Thunderbird involves a WebAssembly (wasm) frame iterator getting stuck in an infinite loop when processing certain w...
Jul 9, 2024IBM InfoSphere Information Server 11.7 discloses sensitive technical error information to remote attackers. This information leakage could reveal syst...
Jun 30, 2024The free5GC UDR component leaks detailed internal parsing error messages to remote clients through the NEF service. This allows attackers to perform s...
Feb 24, 2026The free5GC User Data Repository versions up to 1.4.1 leak detailed internal parsing error messages through the NEF component. This allows remote atta...
Feb 24, 2026The free5GC UDR component versions prior to 1.4.1 leak internal parsing error details to remote clients through the Nnef_PfdManagement service. This i...
Feb 23, 2026About CWE-209 (CWE-209)
Our database tracks 109 CVEs classified as CWE-209, with 12 rated critical and 20 rated high severity. The average CVSS score for CWE-209 vulnerabilities is 6.1.
External reference: View CWE-209 on MITRE CWE →
Monitor CWE-209 Vulnerabilities
Get alerted when new CWE-209 CVEs affect your infrastructure.
Start Monitoring Free