Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2023-40725

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The affected application returns inconsistent error messages in response to invalid user credentials…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37489

Published Sep 12, 2023

Due to the lack of validation, SAP BusinessObjects Business Intelligence Platform (Version Management System) - version 403, permits an unauthenticated user to read the code snipp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39264

Published Sep 6, 2023

By default, stack traces for errors were enabled, which resulted in the exposure of internal traces on REST API endpoints to users. This vulnerability exists in Apache Superset ve…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35124

Published Sep 5, 2023

An information disclosure vulnerability exists in the OAS Engine configuration management functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted s…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40767

Published Aug 28, 2023

User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40766

Published Aug 28, 2023

User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40765

Published Aug 28, 2023

User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determin…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40764

Published Aug 28, 2023

User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40763

Published Aug 28, 2023

User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40762

Published Aug 28, 2023

User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40761

Published Aug 28, 2023

User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40760

Published Aug 28, 2023

User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40759

Published Aug 28, 2023

User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to dete…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40758

Published Aug 28, 2023

User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40757

Published Aug 28, 2023

User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-26272

Published Aug 28, 2023

IBM Security Guardium Data Encryption (IBM Guardium Cloud Key Manager (GCKM) 1.10.3)) could allow a remote attacker to obtain sensitive information when a detailed technical error…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32755

Published Aug 25, 2023

e-Excellence U-Office Force generates an error message in webiste service. An unauthenticated remote attacker can obtain partial sensitive system information from error message by…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40171

Published Aug 17, 2023

Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for signing JWT tokens in error message when the `Dispatch Plugi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35009

Published Aug 16, 2023

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a remote attacker to obtain system information without authentication which could be used in reconnaissance to gather i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1210

Published Aug 2, 2023

An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 befo…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-31429

Published Aug 1, 2023

Brocade Fabric OS before Brocade Fabric OS 9.1.1c, 9.2.0 contains a vulnerability when using various commands such as “chassisdistribute”, “reboot”, “rasman”, errmoduleshow, errfi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4868

Published Jul 31, 2023

IBM TRIRIGA 3.0, 4.0, and 4.4 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 574 CVEsPage 12 of 23