CWE-209: CWE-209

109
Total CVEs
12
Critical
20
High
6.1
Avg CVSS

Yearly Trend

2026
20
2025
43
2024
27
2023
10
2022
5

Top Affected Vendors

1 Ibm 23
2 Phpjabbers 5
3 Gitlab 4
4 Apache 4
5 Hcltech 3
6 Free5gc 3
7 Microsoft 2
8 Aptsys 2
9 Typo3 1
10 Codeigniter 1

All CWE-209 CVEs (109)

CVE-2025-62168
10.0

Squid caching proxy versions before 7.2 fail to properly redact HTTP authentication credentials in error messages, allowing information disclosure. Th...

Oct 17, 2025
CVE-2025-46658
9.8

CVE-2025-46658 is an information disclosure vulnerability in 4C Strategies ExonautWeb where verbose error messages expose sensitive system information...

Aug 5, 2025
CVE-2024-6980
9.8

A verbose error handling issue in the GravityZone Update Server proxy service allows attackers to perform server-side request forgery (SSRF) attacks. ...

Jul 31, 2024
CVE-2024-28285
9.8

CVE-2024-28285 is a fault injection vulnerability in Crypto++'s ElGamal decryption function that allows a co-resident attacker on the same system to e...

May 14, 2024
CVE-2023-40758
9.8

This vulnerability in PHPJabbers Document Creator v1.0 allows attackers to enumerate valid user accounts through the password recovery feature. By obs...

Aug 28, 2023
CVE-2023-40760
9.8

This vulnerability in PHP Jabbers Hotel Booking System v4.0 allows attackers to enumerate valid user accounts through password recovery functionality....

Aug 28, 2023
CVE-2023-40762
9.8

This vulnerability in PHPJabbers Fundraising Script v1.0 allows attackers to enumerate valid user accounts through the password recovery feature. By o...

Aug 28, 2023
CVE-2023-40764
9.8

This vulnerability in PHP Jabbers Car Rental Script v3.0 allows attackers to enumerate valid user accounts through the password recovery feature. By o...

Aug 28, 2023
CVE-2023-40766
9.8

This vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to enumerate valid user accounts through the password recovery feature. B...

Aug 28, 2023
CVE-2022-31229
9.6

Dell PowerScale OneFS versions 8.2.x through 9.3.0.x contain an error message that leaks sensitive information. This vulnerability allows administrato...

Jun 28, 2022
CVE-2023-40171
9.1

This vulnerability in Dispatch's Basic Authentication Provider plugin exposes the JWT secret key in error messages when JWT token decoding fails. Atta...

Aug 17, 2023
CVE-2022-34882
9.0

This vulnerability allows remote authenticated users to obtain sensitive information through error messages in Hitachi RAID Manager Storage Replicatio...

Sep 6, 2022
CVE-2024-23689
8.8

This vulnerability exposes client certificate passwords in exception logs when SSL authentication fails in ClickHouse Java clients. Attackers who can ...

Jan 19, 2024
CVE-2024-54141
8.6

phpMyFAQ versions before 4.0.0 expose database credentials in error messages when database connection fails. This allows attackers to obtain sensitive...

Dec 6, 2024
CVE-2025-22218
8.5

VMware Aria Operations for Logs contains an information disclosure vulnerability where authenticated users with View Only Admin permissions can read c...

Jan 30, 2025
CVE-2025-1395
8.2

This CVE describes an information disclosure vulnerability in HeyGarson software where error messages reveal sensitive information during fuzzing atta...

Jan 30, 2026
CVE-2023-37260
8.2

This vulnerability in league/oauth2-server exposes cryptographic keys in error messages when keys are passed as strings without valid passphrases. Att...

Jul 6, 2023
CVE-2024-11625
7.7

This CVE describes an information exposure vulnerability in Progress Software Corporation's Sitefinity CMS where error messages reveal sensitive syste...

Jan 7, 2025
CVE-2022-31124
7.7

This vulnerability in openssh_key_parser allows attackers to expose sensitive key field values through error messages. Attackers can manipulate declar...

Jul 6, 2022
CVE-2021-32775
7.7

This vulnerability in Combodo iTop allows non-admin users to access sensitive class/field values through error messages in the GroupBy Dashlet. It aff...

Jul 21, 2021
CVE-2022-50686
7.5

This vulnerability in Kentico Xperience allows attackers to view detailed error messages containing sensitive stack trace information through Portal E...

Dec 18, 2025
CVE-2025-36003
7.5

IBM Security Verify Governance Identity Manager 10.0.2 discloses sensitive technical error information to remote attackers. This information leakage v...

Aug 28, 2025
CVE-2025-44203
7.5

An unauthenticated attacker can exploit verbose SQL error messages in HotelDruid 3.0.7 to extract administrator credentials (username, password hash, ...

Jun 20, 2025
CVE-2023-46240
7.5

CodeIgniter4 versions before 4.4.3 display detailed error reports in production environments when errors or exceptions occur, potentially leaking sens...

Oct 31, 2023
CVE-2023-37306
7.5

CVE-2023-37306 is an information disclosure vulnerability in MISP (Malware Information Sharing Platform) where improper handling of certificate file e...

Jun 30, 2023
CVE-2023-25956
7.5

This vulnerability in Apache Airflow AWS Provider versions before 7.2.1 allows error messages to leak sensitive information. Attackers can exploit thi...

Feb 24, 2023
CVE-2022-31140
7.5

This vulnerability in the Valinor PHP library allows attackers to extract sensitive information from error messages that should not be exposed. Attack...

Jul 11, 2022
CVE-2022-2062
7.5

This vulnerability in NocoDB prior to version 0.91.7+ allows error messages to expose sensitive information. Attackers can exploit this to obtain inte...

Jun 13, 2022
CVE-2021-22885
7.5

This vulnerability in Ruby on Rails Action Pack allows attackers to perform information disclosure or unintended method execution when using redirect_...

May 27, 2021
CVE-2021-29688
7.5

IBM Security Identity Manager 7.0.2 returns detailed technical error messages to remote attackers, potentially exposing sensitive system information. ...

May 20, 2021
CVE-2021-20393
7.5

IBM QRadar User Behavior Analytics versions 1.0.0 through 4.1.0 expose detailed technical error messages to remote attackers when errors occur. This i...

May 14, 2021
CVE-2024-45817
7.3

This vulnerability in Xen's x86 APIC implementation allows a malicious guest VM to trigger a deadlock in the hypervisor by configuring error interrupt...

Sep 25, 2024
CVE-2025-65995
6.5

This vulnerability in Apache Airflow allows authenticated users with DAG view permissions to potentially see sensitive information like secrets when a...

Feb 21, 2026
CVE-2025-12773
6.5

A vulnerability in Brocade SANnav's update-reports-purge-settings.sh script logs the database password to system audit logs. This allows authenticated...

Feb 3, 2026
CVE-2025-41076
6.5

This vulnerability allows external users to trigger a 500 error in LimeSurvey by sending malformed session cookies, which exposes sensitive internal s...

Nov 20, 2025
CVE-2023-47728
6.5

This vulnerability allows remote attackers to obtain sensitive technical error information from IBM QRadar Suite and Cloud Pak for Security systems. A...

Aug 16, 2024
CVE-2024-35155
6.5

IBM MQ Console versions 9.3 LTS and 9.3 CD expose detailed technical error messages to remote attackers, potentially revealing sensitive system inform...

Jun 28, 2024
CVE-2024-11129
6.3

This vulnerability in GitLab EE allows attackers to perform targeted searches with sensitive keywords to obtain counts of issues containing those term...

Apr 10, 2025
CVE-2024-52896
6.2

IBM MQ web console versions 9.2-9.4 can leak sensitive technical error information to remote attackers. This information disclosure vulnerability affe...

Dec 19, 2024
CVE-2024-23945
5.9

Apache Hive and Spark expose correct cookie signatures during signature mismatch errors, potentially allowing attackers to forge valid signed cookies....

Dec 23, 2024
CVE-2026-27004
5.5

OpenClaw session tools allowed broader session targeting than intended in shared-agent deployments, potentially exposing transcript content across pee...

Feb 20, 2026
CVE-2026-20838
5.5

This Windows Kernel vulnerability allows authenticated local attackers to extract sensitive information through error messages. Attackers with valid c...

Jan 13, 2026
CVE-2025-40760
5.5

A vulnerability in Altair Grid Engine versions before V2026.0.0 allows local attackers to extract password hashes for privileged accounts through erro...

Nov 11, 2025
CVE-2025-55676
5.5

This vulnerability in the Windows USB Video Driver allows an authorized attacker to read sensitive information from error messages. It affects Windows...

Oct 14, 2025
CVE-2025-5731
5.5

This vulnerability in Infinispan CLI exposes sensitive passwords in error messages when commands fail. Attackers could potentially capture passwords b...

Jun 26, 2025
CVE-2024-6613
5.5

This vulnerability in Firefox and Thunderbird involves a WebAssembly (wasm) frame iterator getting stuck in an infinite loop when processing certain w...

Jul 9, 2024
CVE-2023-50953
5.4

IBM InfoSphere Information Server 11.7 discloses sensitive technical error information to remote attackers. This information leakage could reveal syst...

Jun 30, 2024
CVE-2026-27643
5.3

The free5GC UDR component leaks detailed internal parsing error messages to remote clients through the NEF service. This allows attackers to perform s...

Feb 24, 2026
CVE-2025-69253
5.3

The free5GC User Data Repository versions up to 1.4.1 leak detailed internal parsing error messages through the NEF component. This allows remote atta...

Feb 24, 2026
CVE-2025-69208
5.3

The free5GC UDR component versions prior to 1.4.1 leak internal parsing error details to remote clients through the Nnef_PfdManagement service. This i...

Feb 23, 2026

About CWE-209 (CWE-209)

Our database tracks 109 CVEs classified as CWE-209, with 12 rated critical and 20 rated high severity. The average CVSS score for CWE-209 vulnerabilities is 6.1.

External reference: View CWE-209 on MITRE CWE →

Monitor CWE-209 Vulnerabilities

Get alerted when new CWE-209 CVEs affect your infrastructure.

Start Monitoring Free