Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2023-0655

Published Feb 14, 2023

SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46675

Published Feb 11, 2023

Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22626

Published Jan 5, 2023

PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-10012

Published Jan 3, 2023

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown f…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39304

Published Dec 20, 2022

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20525

Published Dec 16, 2022

In enforceVisualVoicemailPackage of PhoneInterfaceManager.java, there is a possible leak of visual voicemail package name due to a permissions bypass. This could lead to local esc…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39307

Published Nov 9, 2022

Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a POST request is made to the `/api/user/password/sent-reset…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40292

Published Oct 31, 2022

The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42777

Published Oct 29, 2022

Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2508

Published Oct 27, 2022

In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39315

Published Oct 25, 2022

Kirby is a Content Management System. Prior to versions 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, a user enumeration vulnerability affects all Kirby sites with user accounts unless Ki…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38107

Published Oct 19, 2022

Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2760

Published Sep 28, 2022

In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3513

Published Aug 22, 2022

A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33930

Published Aug 10, 2022

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclos…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31189

Published Aug 1, 2022

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. When an "Internal System Err…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 574 CVEsPage 14 of 23