CWE-209 · 592 записей
Generation of Error Message Containing Sensitive Information
CVE этого класса
592 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2024-29059Готовый эксплойт | .NET Framework Information Disclosure Vulnerabilitymicrosoft · .net framework · CWE-209 | Высокая7,5 | KEV | 98,6 % | 22 мар. 2024 г. |
71На этой неделе | CVE-2013-7331Готовый эксплойт | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnamicrosoft · internet explorer · CWE-209 | Средняя6,5 | KEV | 50,2 % | 26 февр. 2014 г. |
66На этой неделе | CVE-2025-47813Готовый эксплойт | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UIwftpserver · wing ftp server · CWE-209 | Средняя4,3 | KEV | 63,0 % | 10 июл. 2025 г. |
49В плане | CVE-2025-62168Proof of concept | Squid vulnerable to information disclosure via authentication credential leakage in error handlingsquid-cache · squid · CWE-209 | Высокая7,5 | — | 63,4 % | 17 окт. 2025 г. |
45В плане | CVE-2010-3332Proof of concept | Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servimicrosoft · .net framework · CWE-209 | Средняя6,4 | — | 68,2 % | 22 сент. 2010 г. |
40В плане | CVE-2018-11325Эксплойта нет | An issue was discovered in Joomla! Core before 3.8.8.joomla · joomla\! · CWE-209 | Критическая9,8 | — | 3,2 % | 22 мая 2018 г. |
40В плане | CVE-2019-7612Эксплойта нет | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.elastic · logstash · CWE-209 | Критическая9,8 | — | 2,4 % | 25 мар. 2019 г. |
40В плане | CVE-2017-7945Эксплойта нет | The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2paloaltonetworks · pan-os · CWE-209 | Критическая9,8 | — | 1,8 % | 28 апр. 2017 г. |
40В плане | CVE-2019-7644Эксплойта нет | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT sauth0 · auth0-wcf-service-jwt · CWE-209 | Критическая9,8 | — | 1,7 % | 11 апр. 2019 г. |
39Наблюдать | CVE-2018-14925Эксплойта нет | Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.matera · banco · CWE-209 | Критическая9,8 | — | 1,5 % | 3 авг. 2018 г. |
39Наблюдать | CVE-2017-7551Эксплойта нет | 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different returfedoraproject · 389 directory server · CWE-209 | Критическая9,8 | — | 1,4 % | 16 авг. 2017 г. |
39Наблюдать | CVE-2023-40763Эксплойта нет | User enumeration is found in PHPJabbers Taxi Booking Script v2.0.phpjabbers · taxi booking script · CWE-209 | Критическая9,8 | — | 1,1 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2021-42777Эксплойта нет | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macstimulsoft · reports · CWE-209 | Критическая9,8 | — | 1,0 % | 29 окт. 2022 г. |
39Наблюдать | CVE-2023-40759Эксплойта нет | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.phpjabbers · restaurant booking script · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40767Эксплойта нет | User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.phpjabbers · make an offer widget · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40760Эксплойта нет | User enumeration is found in PHP Jabbers Hotel Booking System v4.0.phpjabbers · hotel booking system · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40761Эксплойта нет | User enumeration is found in PHPJabbers Yacht Listing Script v2.0.phpjabbers · yacht listing script · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40762Эксплойта нет | User enumeration is found in PHPJabbers Fundraising Script v1.0.phpjabbers · fundraising script · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40764Эксплойта нет | User enumeration is found in PHP Jabbers Car Rental Script v3.0.phpjabbers · car rental script · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40766Эксплойта нет | User enumeration is found in in PHPJabbers Ticket Support Script v3.2.phpjabbers · ticket support script · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40765Эксплойта нет | User enumeration is found in PHPJabbers Event Booking Calendar v4.0.phpjabbers · event booking calendar · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40757Эксплойта нет | User enumeration is found in PHPJabbers Food Delivery Script v3.1.phpjabbers · food delivery script · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2023-40758Эксплойта нет | User enumeration is found in PHPJabbers Document Creator v1.0.phpjabbers · document creator · CWE-209 | Критическая9,8 | — | 0,9 % | 28 авг. 2023 г. |
39Наблюдать | CVE-2024-28285Эксплойта нет | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reCWE-209 | Критическая9,8 | — | 0,5 % | 14 мая 2024 г. |
39Наблюдать | CVE-2025-59872Эксплойта нет | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,hcltech · zie for web · CWE-209 | Критическая9,8 | — | 0,5 % | 17 июн. 2026 г. |
- CVE-2024-2905990Срочно
.NET Framework Information Disclosure Vulnerability
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 99 %microsoft · .net framework22 мар. 2024 г.
- CVE-2013-733171На этой неделе
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathna
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 50 %microsoft · internet explorer26 февр. 2014 г.
- CVE-2025-4781366На этой неделе
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI
СредняяCVSS 4,3KEVГотовый эксплойтEPSS 63 %wftpserver · wing ftp server10 июл. 2025 г.
- CVE-2025-6216849В плане
Squid vulnerable to information disclosure via authentication credential leakage in error handling
ВысокаяCVSS 7,5Proof of conceptEPSS 63 %squid-cache · squid17 окт. 2025 г.
- CVE-2010-333245В плане
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servi
СредняяCVSS 6,4Proof of conceptEPSS 68 %microsoft · .net framework22 сент. 2010 г.
- CVE-2018-1132540В плане
An issue was discovered in Joomla! Core before 3.8.8.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %joomla · joomla\!22 мая 2018 г.
- CVE-2019-761240В плане
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %elastic · logstash25 мар. 2019 г.
- CVE-2017-794540В плане
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %paloaltonetworks · pan-os28 апр. 2017 г.
- CVE-2019-764440В плане
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %auth0 · auth0-wcf-service-jwt11 апр. 2019 г.
- CVE-2018-1492539Наблюдать
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %matera · banco3 авг. 2018 г.
- CVE-2017-755139Наблюдать
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different retur
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %fedoraproject · 389 directory server16 авг. 2017 г.
- CVE-2023-4076339Наблюдать
User enumeration is found in PHPJabbers Taxi Booking Script v2.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · taxi booking script28 авг. 2023 г.
- CVE-2021-4277739Наблюдать
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %stimulsoft · reports29 окт. 2022 г.
- CVE-2023-4075939Наблюдать
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · restaurant booking script28 авг. 2023 г.
- CVE-2023-4076739Наблюдать
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · make an offer widget28 авг. 2023 г.
- CVE-2023-4076039Наблюдать
User enumeration is found in PHP Jabbers Hotel Booking System v4.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · hotel booking system28 авг. 2023 г.
- CVE-2023-4076139Наблюдать
User enumeration is found in PHPJabbers Yacht Listing Script v2.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · yacht listing script28 авг. 2023 г.
- CVE-2023-4076239Наблюдать
User enumeration is found in PHPJabbers Fundraising Script v1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · fundraising script28 авг. 2023 г.
- CVE-2023-4076439Наблюдать
User enumeration is found in PHP Jabbers Car Rental Script v3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · car rental script28 авг. 2023 г.
- CVE-2023-4076639Наблюдать
User enumeration is found in in PHPJabbers Ticket Support Script v3.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · ticket support script28 авг. 2023 г.
- CVE-2023-4076539Наблюдать
User enumeration is found in PHPJabbers Event Booking Calendar v4.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · event booking calendar28 авг. 2023 г.
- CVE-2023-4075739Наблюдать
User enumeration is found in PHPJabbers Food Delivery Script v3.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · food delivery script28 авг. 2023 г.
- CVE-2023-4075839Наблюдать
User enumeration is found in PHPJabbers Document Creator v1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %phpjabbers · document creator28 авг. 2023 г.
- CVE-2024-2828539Наблюдать
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %14 мая 2024 г.
- CVE-2025-5987239Наблюдать
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %hcltech · zie for web17 июн. 2026 г.