CWE-209: CWE-209

109
Total CVEs
12
Critical
20
High
6.1
Avg CVSS

Yearly Trend

2026
20
2025
43
2024
27
2023
10
2022
5

Top Affected Vendors

1 Ibm 23
2 Phpjabbers 5
3 Gitlab 4
4 Apache 4
5 Hcltech 3
6 Free5gc 3
7 Microsoft 2
8 Aptsys 2
9 Typo3 1
10 Codeigniter 1

All CWE-209 CVEs (109)

CVE-2022-22363
4.3

CVE-2022-22363 is an information disclosure vulnerability in IBM Cognos Controller and IBM Controller that exposes detailed technical error messages t...

Jan 7, 2025
CVE-2024-49818
4.3

IBM Security Guardium Key Lifecycle Manager versions 4.1 through 4.2.1 expose detailed technical error messages to remote attackers, potentially revea...

Dec 17, 2024
CVE-2024-51560
4.3

This vulnerability in Wave 2.0 allows authenticated attackers to trigger error messages containing sensitive information by sending invalid inputs to ...

Nov 4, 2024
CVE-2024-47803
4.3

Jenkins versions 2.478 and earlier (including LTS 2.462.2 and earlier) fail to properly redact multi-line secret values in error messages when form su...

Oct 2, 2024
CVE-2024-43376
4.3

This vulnerability in Umbraco CMS allows attackers to obtain stack trace information from Management API endpoints even when debug mode is disabled. T...

Aug 20, 2024
CVE-2025-49128
4.0

This vulnerability in Jackson-core allows up to 500 bytes of unintended memory content to leak in exception messages when parsing JSON from byte array...

Jun 6, 2025
CVE-2025-62840
3.3

This vulnerability in QNAP HBS 3 Hybrid Backup Sync allows error messages to expose sensitive application data. Attackers with local network access ca...

Jan 2, 2026
CVE-2025-66549
2.4

Nextcloud Desktop client versions before 3.16.5 send file paths unencrypted to the server when manually locking files in end-to-end encrypted director...

Dec 5, 2025
CVE-2025-55250
1.8

HCL AION version 2 contains a technical error disclosure vulnerability that can expose sensitive system details through error messages. This affects o...

Jan 19, 2026

About CWE-209 (CWE-209)

Our database tracks 109 CVEs classified as CWE-209, with 12 rated critical and 20 rated high severity. The average CVSS score for CWE-209 vulnerabilities is 6.1.

External reference: View CWE-209 on MITRE CWE →

Monitor CWE-209 Vulnerabilities

Get alerted when new CWE-209 CVEs affect your infrastructure.

Start Monitoring Free