CWE-209: CWE-209
Yearly Trend
Top Affected Vendors
All CWE-209 CVEs (109)
This vulnerability in Yokogawa's FAST/TOOLS software exposes detailed error messages that could reveal sensitive system information. Attackers could l...
Feb 9, 2026IBM Cloud Pak System contains a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious JavaScript into the web interface. ...
Feb 4, 2026IBM Cloud Pak System fails to set the secure attribute on authorization tokens and session cookies, making them vulnerable to interception when transm...
Feb 4, 2026IBM Cloud Pak System displays sensitive information in user messages that could aid attackers. This information disclosure vulnerability affects IBM C...
Feb 4, 2026This vulnerability in the go-viper/mapstructure library allows information disclosure through detailed error messages that leak sensitive input values...
Jan 26, 2026This vulnerability in gemscms.aptsys.com.sg's PHP backend allows unauthenticated remote attackers to trigger detailed error messages that disclose int...
Jan 23, 2026This vulnerability allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and st...
Jan 23, 2026The Fancy Product Designer WordPress plugin up to version 6.4.8 exposes server filesystem paths and stack traces in error messages through its PDF upl...
Jan 16, 2026This vulnerability in Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework exposes detailed server stack traces throug...
Dec 15, 2025This vulnerability involves error messages being exposed in HTTP headers, potentially leaking sensitive information about the system. It affects BLU-I...
Oct 27, 2025This vulnerability allows attackers to enumerate valid course IDs on a router by observing inconsistent responses to invalid IDs. This information dis...
Oct 23, 2025This vulnerability allows unauthenticated remote attackers to determine whether specific projects exist in Canonical LXD by observing different HTTP s...
Oct 2, 2025An information disclosure vulnerability in MiR robot software allows unauthenticated attackers to access detailed error information including file pat...
Aug 20, 2025HCL BigFix SaaS Authentication Service discloses sensitive version information through error messages under certain conditions. This information discl...
Aug 15, 2025This vulnerability in OMERO.web's password reset functionality allows information disclosure about users when password reset errors occur. Attackers c...
Aug 13, 2025IBM Analytics Content Hub versions 2.0-2.3 expose sensitive information through detailed error messages returned to browsers. This information disclos...
Jul 10, 2025An unauthenticated remote attacker can enumerate valid LDAP usernames on vulnerable Cisco Nexus Dashboard systems by sending authentication requests. ...
Apr 16, 2025The C9 Blocks WordPress plugin contains a publicly accessible file (composer-setup.php) that discloses the full server path when accessed. This affect...
Feb 21, 2025The BigBuy Dropshipping Connector for WooCommerce WordPress plugin discloses the full server path through an accessible vendor file that triggers an e...
Feb 18, 2025The AForms Eats WordPress plugin discloses full server path information through a publicly accessible vendor file. This information disclosure vulnera...
Feb 12, 2025IBM Analytics Content Hub 2.0 discloses sensitive technical error information to remote attackers via browser responses. This information leakage coul...
Jan 25, 2025IBM Cloud Pak System versions 2.3.3.0 through 2.3.3.7 iFix1 contain an information disclosure vulnerability that could expose sensitive system details...
Jan 25, 2025This CVE describes an information disclosure vulnerability in the Paytium WordPress plugin where error messages reveal sensitive information like full...
Jan 24, 2025SAP NetWeaver Application Server for ABAP and ABAP Platform contains an information disclosure vulnerability where unauthenticated attackers can acces...
Jan 14, 2025This vulnerability in IBM Engineering Lifecycle Optimization - Engineering Insights allows remote attackers to obtain sensitive information through de...
Dec 25, 2024This vulnerability in the Vimeography WordPress plugin exposes sensitive information through error messages, potentially revealing full server paths. ...
Dec 16, 2024This vulnerability in HumHub allows attackers to enumerate valid usernames through error messages that leak sensitive information. All HumHub installa...
Nov 6, 2024This vulnerability in the Posti Shipping WordPress plugin allows attackers to retrieve sensitive information through error messages. It affects all ve...
Oct 30, 2024This vulnerability in Webmin Usermin v2.100 allows attackers to distinguish between valid and invalid user accounts through differences in error messa...
Oct 16, 2024A padding oracle vulnerability in Apache Druid's optional druid-pac4j extension could allow attackers to manipulate session cookies. This affects Drui...
Sep 17, 2024This vulnerability in Drupal 11.x-dev allows Full Path Disclosure when the hash_salt configuration points to a non-existent file. Attackers can exploi...
Aug 29, 2024IBM InfoSphere Information Server 11.7 discloses sensitive technical information in error messages, potentially revealing system details that could ai...
Jun 30, 2024This vulnerability in Italtel Embrace 1.6.4 allows unauthenticated attackers to trigger application errors that reveal sensitive server information li...
May 21, 2024SolarWinds Kiwi CatTools can disclose sensitive information when a non-default troubleshooting setting is enabled. This affects administrators who hav...
Oct 17, 2024This vulnerability in Android's RemotePrintDocument component allows local information disclosure through a logic error in writeContent. It affects An...
Sep 4, 2025This vulnerability in IBM Sterling B2B Integrator and File Gateway exposes sensitive technical error messages to remote privileged attackers. Attacker...
Feb 17, 2026HCL BigFix Compliance generates error messages that may leak sensitive information about the system environment, users, or associated data. This vulne...
Nov 7, 2024CVE-2025-4166 allows sensitive information exposure in Vault server and audit logs when users submit malformed payloads during secret creation or upda...
May 2, 2025This vulnerability in GitLab EE/CE allows attackers to retrieve user passwords stored in repository mirror configurations. It affects GitLab instances...
Sep 12, 2024This vulnerability in GitLab EE/CE allows sensitive authentication information to be exposed through repository mirroring settings. Attackers could po...
Mar 13, 2025This CVE describes an information disclosure vulnerability where error messages reveal internal system details like file paths, database errors, or so...
Jan 15, 2026This vulnerability allows authenticated users to discover the names of private projects they shouldn't have access to through API requests. It affects...
Dec 11, 2025This vulnerability in IBM Planning Analytics Local versions 2.1.0 through 2.1.15 allows attackers to obtain sensitive information about server archite...
Dec 9, 2025This vulnerability allows non-admin users to view detailed debug information in SQL error messages, revealing software, PHP, and database version deta...
Nov 20, 2025This vulnerability in Desktop Alert PingAlert's Application Server (versions 6.1.0.11 to 6.1.1.2) allows attackers to obtain technical information thr...
Nov 14, 2025This vulnerability allows authenticated backend users in TYPO3 CMS to obtain sensitive file path information through error messages when file operatio...
Sep 9, 2025IBM Verify Identity Access Digital Credentials 24.06 returns detailed technical error messages to browsers, potentially exposing sensitive system info...
Jun 6, 2025IBM Security Guardium 12.0 discloses sensitive technical error information to remote attackers via browser responses. This information leakage could e...
May 28, 2025IBM ApplinX 11.1 can expose sensitive technical error information to remote attackers through browser responses. This information disclosure vulnerabi...
Feb 6, 2025IBM Control Center versions 6.2.1 and 6.3.1 expose detailed technical error messages to remote attackers, potentially revealing sensitive system infor...
Jan 25, 2025About CWE-209 (CWE-209)
Our database tracks 109 CVEs classified as CWE-209, with 12 rated critical and 20 rated high severity. The average CVSS score for CWE-209 vulnerabilities is 6.1.
External reference: View CWE-209 on MITRE CWE →
Monitor CWE-209 Vulnerabilities
Get alerted when new CWE-209 CVEs affect your infrastructure.
Start Monitoring Free