CWE-209 · 592 records
Generation of Error Message Containing Sensitive Information
CVEs in this class
592 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2024-29059Weaponized | .NET Framework Information Disclosure Vulnerabilitymicrosoft · .net framework · CWE-209 | High7.5 | KEV | 98.6% | Mar 22, 2024 |
71This week | CVE-2013-7331Weaponized | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnamicrosoft · internet explorer · CWE-209 | Medium6.5 | KEV | 50.2% | Feb 26, 2014 |
66This week | CVE-2025-47813Weaponized | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UIwftpserver · wing ftp server · CWE-209 | Medium4.3 | KEV | 63.0% | Jul 10, 2025 |
49Plan | CVE-2025-62168Proof of concept | Squid vulnerable to information disclosure via authentication credential leakage in error handlingsquid-cache · squid · CWE-209 | High7.5 | — | 63.4% | Oct 17, 2025 |
45Plan | CVE-2010-3332Proof of concept | Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servimicrosoft · .net framework · CWE-209 | Medium6.4 | — | 68.2% | Sep 22, 2010 |
40Plan | CVE-2018-11325No exploit | An issue was discovered in Joomla! Core before 3.8.8.joomla · joomla\! · CWE-209 | Critical9.8 | — | 3.2% | May 22, 2018 |
40Plan | CVE-2019-7612No exploit | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.elastic · logstash · CWE-209 | Critical9.8 | — | 2.4% | Mar 25, 2019 |
40Plan | CVE-2017-7945No exploit | The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2paloaltonetworks · pan-os · CWE-209 | Critical9.8 | — | 1.8% | Apr 28, 2017 |
40Plan | CVE-2019-7644No exploit | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT sauth0 · auth0-wcf-service-jwt · CWE-209 | Critical9.8 | — | 1.7% | Apr 11, 2019 |
39Monitor | CVE-2018-14925No exploit | Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.matera · banco · CWE-209 | Critical9.8 | — | 1.5% | Aug 3, 2018 |
39Monitor | CVE-2017-7551No exploit | 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different returfedoraproject · 389 directory server · CWE-209 | Critical9.8 | — | 1.4% | Aug 16, 2017 |
39Monitor | CVE-2023-40763No exploit | User enumeration is found in PHPJabbers Taxi Booking Script v2.0.phpjabbers · taxi booking script · CWE-209 | Critical9.8 | — | 1.1% | Aug 28, 2023 |
39Monitor | CVE-2021-42777No exploit | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macstimulsoft · reports · CWE-209 | Critical9.8 | — | 1.0% | Oct 29, 2022 |
39Monitor | CVE-2023-40759No exploit | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.phpjabbers · restaurant booking script · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40767No exploit | User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.phpjabbers · make an offer widget · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40760No exploit | User enumeration is found in PHP Jabbers Hotel Booking System v4.0.phpjabbers · hotel booking system · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40761No exploit | User enumeration is found in PHPJabbers Yacht Listing Script v2.0.phpjabbers · yacht listing script · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40762No exploit | User enumeration is found in PHPJabbers Fundraising Script v1.0.phpjabbers · fundraising script · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40764No exploit | User enumeration is found in PHP Jabbers Car Rental Script v3.0.phpjabbers · car rental script · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40766No exploit | User enumeration is found in in PHPJabbers Ticket Support Script v3.2.phpjabbers · ticket support script · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40765No exploit | User enumeration is found in PHPJabbers Event Booking Calendar v4.0.phpjabbers · event booking calendar · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40757No exploit | User enumeration is found in PHPJabbers Food Delivery Script v3.1.phpjabbers · food delivery script · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2023-40758No exploit | User enumeration is found in PHPJabbers Document Creator v1.0.phpjabbers · document creator · CWE-209 | Critical9.8 | — | 0.9% | Aug 28, 2023 |
39Monitor | CVE-2024-28285No exploit | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reCWE-209 | Critical9.8 | — | 0.5% | May 14, 2024 |
39Monitor | CVE-2025-59872No exploit | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,hcltech · zie for web · CWE-209 | Critical9.8 | — | 0.5% | Jun 17, 2026 |
- CVE-2024-2905990Now
.NET Framework Information Disclosure Vulnerability
HighCVSS 7.5KEVWeaponizedEPSS 99%microsoft · .net frameworkMar 22, 2024
- CVE-2013-733171This week
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathna
MediumCVSS 6.5KEVWeaponizedEPSS 50%microsoft · internet explorerFeb 26, 2014
- CVE-2025-4781366This week
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI
MediumCVSS 4.3KEVWeaponizedEPSS 63%wftpserver · wing ftp serverJul 10, 2025
- CVE-2025-6216849Plan
Squid vulnerable to information disclosure via authentication credential leakage in error handling
HighCVSS 7.5Proof of conceptEPSS 63%squid-cache · squidOct 17, 2025
- CVE-2010-333245Plan
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servi
MediumCVSS 6.4Proof of conceptEPSS 68%microsoft · .net frameworkSep 22, 2010
- CVE-2018-1132540Plan
An issue was discovered in Joomla! Core before 3.8.8.
CriticalCVSS 9.8No exploitEPSS 3%joomla · joomla\!May 22, 2018
- CVE-2019-761240Plan
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
CriticalCVSS 9.8No exploitEPSS 2%elastic · logstashMar 25, 2019
- CVE-2017-794540Plan
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2
CriticalCVSS 9.8No exploitEPSS 2%paloaltonetworks · pan-osApr 28, 2017
- CVE-2019-764440Plan
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s
CriticalCVSS 9.8No exploitEPSS 2%auth0 · auth0-wcf-service-jwtApr 11, 2019
- CVE-2018-1492539Monitor
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
CriticalCVSS 9.8No exploitEPSS 2%matera · bancoAug 3, 2018
- CVE-2017-755139Monitor
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different retur
CriticalCVSS 9.8No exploitEPSS 1%fedoraproject · 389 directory serverAug 16, 2017
- CVE-2023-4076339Monitor
User enumeration is found in PHPJabbers Taxi Booking Script v2.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · taxi booking scriptAug 28, 2023
- CVE-2021-4277739Monitor
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac
CriticalCVSS 9.8No exploitEPSS 1%stimulsoft · reportsOct 29, 2022
- CVE-2023-4075939Monitor
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · restaurant booking scriptAug 28, 2023
- CVE-2023-4076739Monitor
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · make an offer widgetAug 28, 2023
- CVE-2023-4076039Monitor
User enumeration is found in PHP Jabbers Hotel Booking System v4.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · hotel booking systemAug 28, 2023
- CVE-2023-4076139Monitor
User enumeration is found in PHPJabbers Yacht Listing Script v2.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · yacht listing scriptAug 28, 2023
- CVE-2023-4076239Monitor
User enumeration is found in PHPJabbers Fundraising Script v1.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · fundraising scriptAug 28, 2023
- CVE-2023-4076439Monitor
User enumeration is found in PHP Jabbers Car Rental Script v3.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · car rental scriptAug 28, 2023
- CVE-2023-4076639Monitor
User enumeration is found in in PHPJabbers Ticket Support Script v3.2.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · ticket support scriptAug 28, 2023
- CVE-2023-4076539Monitor
User enumeration is found in PHPJabbers Event Booking Calendar v4.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · event booking calendarAug 28, 2023
- CVE-2023-4075739Monitor
User enumeration is found in PHPJabbers Food Delivery Script v3.1.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · food delivery scriptAug 28, 2023
- CVE-2023-4075839Monitor
User enumeration is found in PHPJabbers Document Creator v1.0.
CriticalCVSS 9.8No exploitEPSS 1%phpjabbers · document creatorAug 28, 2023
- CVE-2024-2828539Monitor
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re
CriticalCVSS 9.8No exploitEPSS 1%May 14, 2024
- CVE-2025-5987239Monitor
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
CriticalCVSS 9.8No exploitEPSS 0%hcltech · zie for webJun 17, 2026