Skip to main content

CWE archive

CWE-1295 CVEs

Programmatic archive

21 CVEs tagged with CWE-12951 Critical, 4 High, 13 Medium, 3 Low, 0 Unrated.

CVE-2026-48797

Published Jun 17, 2026

Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane w…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-59109

Published Jan 26, 2026

The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can…

CVSS 5.1 · Medium

CVE-2025-12910

Published Nov 8, 2025

Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium sec…

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-35031

Published Sep 29, 2025

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker,…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-42604

Published Apr 23, 2025

This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unau…

CVSS 6.9 · Medium

CVE-2025-2469

Published Apr 10, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessi…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-31001

Published Apr 1, 2025

Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit gtm-kit allows Retrieve Embedded Sensitive Data.This issue affects GTM Kit: from n/a through <=…

CVSS 7.5 · High

CVE-2025-2877

Published Mar 28, 2025

A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when…

CVSS 6.5 · Medium

CVE-2024-11217

Published Nov 15, 2024

A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

CVSS 4.9 · Medium

CVE-2024-45784

Published Nov 15, 2024

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38516

Published Jun 25, 2024

ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched…

CVSS 8.8 · High

CVE-2024-27179

Published Jun 14, 2024

Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the refer…

CVSS 4.7 · Medium

CVE-2023-5392

Published Apr 11, 2024

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most rece…

CVSS 7.5 · High

CVE-2023-28077

Published Feb 10, 2024

Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive in…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4215

Published Oct 17, 2023

Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27597

Published Mar 29, 2023

A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret val…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9

CVE-2022-34364

Published Feb 10, 2023

Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25476

Published Oct 6, 2021

An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31412

Published Jun 24, 2021

Improper sanitization of path in default RouteNotFoundError view in com.vaadin:flow-server versions 1.0.0 through 1.0.14 (Vaadin 10.0.0 through 10.0.18), 1.1.0 prior to 2.0.0 (Vaa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1