Skip to content
Noroxi

CWE-209 · 592 records

Generation of Error Message Containing Sensitive Information

CVEs in this class

592 records

  • .NET Framework Information Disclosure Vulnerability

    HighCVSS 7.5KEVWeaponizedEPSS 99%

    microsoft · .net frameworkMar 22, 2024

  • CVE-2013-7331
    71This week

    The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathna

    MediumCVSS 6.5KEVWeaponizedEPSS 50%

    microsoft · internet explorerFeb 26, 2014

  • CVE-2025-47813
    66This week

    loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI

    MediumCVSS 4.3KEVWeaponizedEPSS 63%

    wftpserver · wing ftp serverJul 10, 2025

  • Squid vulnerable to information disclosure via authentication credential leakage in error handling

    HighCVSS 7.5Proof of conceptEPSS 63%

    squid-cache · squidOct 17, 2025

  • Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servi

    MediumCVSS 6.4Proof of conceptEPSS 68%

    microsoft · .net frameworkSep 22, 2010

  • An issue was discovered in Joomla! Core before 3.8.8.

    CriticalCVSS 9.8No exploitEPSS 3%

    joomla · joomla\!May 22, 2018

  • A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.

    CriticalCVSS 9.8No exploitEPSS 2%

    elastic · logstashMar 25, 2019

  • The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2

    CriticalCVSS 9.8No exploitEPSS 2%

    paloaltonetworks · pan-osApr 28, 2017

  • Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s

    CriticalCVSS 9.8No exploitEPSS 2%

    auth0 · auth0-wcf-service-jwtApr 11, 2019

  • Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.

    CriticalCVSS 9.8No exploitEPSS 2%

    matera · bancoAug 3, 2018

  • CVE-2017-7551
    39Monitor

    389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different retur

    CriticalCVSS 9.8No exploitEPSS 1%

    fedoraproject · 389 directory serverAug 16, 2017

  • User enumeration is found in PHPJabbers Taxi Booking Script v2.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · taxi booking scriptAug 28, 2023

  • Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac

    CriticalCVSS 9.8No exploitEPSS 1%

    stimulsoft · reportsOct 29, 2022

  • User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · restaurant booking scriptAug 28, 2023

  • User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · make an offer widgetAug 28, 2023

  • User enumeration is found in PHP Jabbers Hotel Booking System v4.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · hotel booking systemAug 28, 2023

  • User enumeration is found in PHPJabbers Yacht Listing Script v2.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · yacht listing scriptAug 28, 2023

  • User enumeration is found in PHPJabbers Fundraising Script v1.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · fundraising scriptAug 28, 2023

  • User enumeration is found in PHP Jabbers Car Rental Script v3.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · car rental scriptAug 28, 2023

  • User enumeration is found in in PHPJabbers Ticket Support Script v3.2.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · ticket support scriptAug 28, 2023

  • User enumeration is found in PHPJabbers Event Booking Calendar v4.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · event booking calendarAug 28, 2023

  • User enumeration is found in PHPJabbers Food Delivery Script v3.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · food delivery scriptAug 28, 2023

  • User enumeration is found in PHPJabbers Document Creator v1.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    phpjabbers · document creatorAug 28, 2023

  • A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re

    CriticalCVSS 9.8No exploitEPSS 1%

    May 14, 2024

  • HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,

    CriticalCVSS 9.8No exploitEPSS 0%

    hcltech · zie for webJun 17, 2026

All vulnerability classes