Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2024-23689

Published Jan 19, 2024

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 all…

CVSS 8.8 · High
evidence mentions
6
Buzz score
34.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-21733

Published Jan 19, 2024

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50348

Published Jan 3, 2024

HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the a…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-45701

Published Dec 28, 2023

HCL Launch could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in furt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27319

Published Dec 21, 2023

ONTAP Mediator versions prior to 1.7 are susceptible to a vulnerability that can allow an unauthenticated attacker to enumerate URLs via REST API.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42013

Published Dec 20, 2023

IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.14, 7.2 through 7.2.3.7, and 7.3 through 7.3.2.2 could allow a remote attacker to obtain sensitive information when a detailed technic…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6839

Published Dec 15, 2023

Due to improper error handling, a REST API resource could expose a server side error containing an internal WSO2 specific package name in the HTTP response.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48393

Published Dec 15, 2023

Kaifa Technology WebITR is an online attendance system. A remote attacker with regular user privilege can obtain partial sensitive system information from error message.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49878

Published Dec 13, 2023

IBM System Storage Virtualization Engine TS7700 3957-VEC, 3948-VED and 3957-VEC could allow a remote attacker to obtain sensitive information when a detailed technical error messa…

CVSS 4.3 · Medium

CVE-2023-31048

Published Dec 12, 2023

The OPC UA .NET Standard Reference Server before 1.4.371.86. places sensitive information into an error message that may be seen remotely.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49080

Published Dec 4, 2023

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. Unhandled err…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-47636

Published Nov 15, 2023

The Pimcore Admin Classic Bundle provides a Backend UI for Pimcore. Full Path Disclosure (FPD) vulnerabilities enable the attacker to see the path to the webroot/file. e.g.: /home…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5514

Published Nov 1, 2023

The response messages received from the eSOMS report generation using certain parameter queries with full file path can be abused for enumerating the local file system structure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46240

Published Oct 31, 2023

CodeIgniter is a PHP full-stack web framework. Prior to CodeIgniter4 version 4.4.3, if an error or exception occurs, a detailed error report is displayed even if in the production…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4457

Published Oct 16, 2023

Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information di…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42475

Published Oct 10, 2023

The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentialit…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0833

Published Sep 27, 2023

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an i…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 574 CVEsPage 11 of 23