Skip to main content

CWE archive

CWE-209 CVEs

Programmatic archive

574 CVEs tagged with CWE-20927 Critical, 74 High, 394 Medium, 78 Low, 1 Unrated.

CVE-2022-31140

Published Jul 11, 2022

Valinor is a PHP library that helps to map any input into a strongly-typed value object structure. Prior to version 0.12.0, Valinor can use `Throwable#getMessage()` when it should…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31229

Published Jun 28, 2022

Dell PowerScale OneFS, 8.2.x through 9.3.0.x, contain an error message with sensitive information. An administrator could potentially exploit this vulnerability, leading to disclo…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-31047

Published Jun 14, 2022

TYPO3 is an open source web content management system. Prior to versions 7.6.57 ELTS, 8.7.47 ELTS, 9.5.34 ELTS, 10.4.29, and 11.5.11, system internal credentials or keys (e.g. dat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2062

Published Jun 13, 2022

Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31023

Published Jun 2, 2022

Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26973

Published Jun 2, 2022

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaking the license file name, the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24906

Published May 20, 2022

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is reco…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-26070

Published May 6, 2022

When handling a mismatched pre-authentication cookie, the application leaks the internal error message in the response, which contains the Splunk Enterprise local system path. The…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39023

Published May 6, 2022

IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43206

Published May 4, 2022

A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.x, 6.0.x and FortiProxy 7.0.0 through 7.0.1, 2.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29266

Published Apr 20, 2022

In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt cont…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1120

Published Apr 4, 2022

Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 exposed sensitive information when an…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23794

Published Mar 30, 2022

An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Uploading a file name of an excess length causes the error. This error brings up the screen with the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24731

Published Mar 23, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35251

Published Mar 10, 2022

Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installat…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46353

Published Mar 4, 2022

An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowled…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3620

Published Mar 3, 2022

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error mes…

CVSS 5.5 · Medium

CVE-2022-0660

Published Feb 18, 2022

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-0622

Published Feb 17, 2022

Generation of Error Message Containing Sensitive Information in Packagist snipe/snipe-it prior to 5.3.11.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26726

Published Feb 16, 2022

A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects:…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 574 CVEsPage 15 of 23