Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2023-3362

Published Jul 13, 2023

An information disclosure issue in GitLab CE/EE affecting all versions from 16.0 prior to 16.0.6, and version 16.1.0 allows unauthenticated actors to access the import error infor…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37260

Published Jul 6, 2023

league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2 and prior to version 8.5.3, servers that passed their keys…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37306

Published Jun 30, 2023

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34110

Published Jun 22, 2023

Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-34339

Published Jun 1, 2023

In JetBrains Ktor before 2.3.1 headers containing authentication data could be added to the exception's message

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-33181

Published May 30, 2023

Xibo is a content management system (CMS). Starting in version 3.0.0 and prior to version 3.3.5, some API routes will print a stack trace when called with missing or invalid param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4870

Published May 18, 2023

In affected versions of Octopus Deploy it is possible to discover network details via error message

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21103

Published May 15, 2023

In registerPhoneAccount of PhoneAccountRegistrar.java, uncaught exceptions in parsing persisted user data could lead to local persistent denial of service with no additional execu…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27860

Published Apr 27, 2023

IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could disclose sensitive information in an error message. This information could be used in further attacks against the system. I…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31286

Published Apr 27, 2023

An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to r…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29193

Published Apr 14, 2023

SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a fl…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25687

Published Mar 21, 2023

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25695

Published Mar 15, 2023

Generation of Error Message Containing Sensitive Information vulnerability in Apache Software Foundation Apache Airflow.This issue affects Apache Airflow: before 2.5.2.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27587

Published Mar 13, 2023

ReadtoMyShoe, a web app that lets users upload articles and listen to them later, generates an error message containing sensitive information prior to commit 8533b01. If an error…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26052

Published Mar 2, 2023

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-26051

Published Mar 2, 2023

Saleor is a headless, GraphQL commerce platform delivering personalized shopping experiences. Some internal Python exceptions are not handled properly and thus are returned in API…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5026

Published Mar 1, 2023

IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.7 could allow a remote attacker to obtain sensitive information when a detailed technic…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25956

Published Feb 24, 2023

Generation of Error Message Containing Sensitive Information vulnerability in the Apache Airflow AWS Provider. This issue affects Apache Airflow AWS Provider versions before 7.2.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 301-325 of 574 CVEsPage 13 of 23