CWE-209 · 592 kayıt
Generation of Error Message Containing Sensitive Information
Bu sınıftaki CVE’ler
592 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2024-29059Silahlaştırılmış | .NET Framework Information Disclosure Vulnerabilitymicrosoft · .net framework · CWE-209 | Yüksek7,5 | KEV | %98,6 | 22 Mar 2024 |
71Bu hafta | CVE-2013-7331Silahlaştırılmış | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnamicrosoft · internet explorer · CWE-209 | Orta6,5 | KEV | %50,2 | 26 Şub 2014 |
66Bu hafta | CVE-2025-47813Silahlaştırılmış | loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UIwftpserver · wing ftp server · CWE-209 | Orta4,3 | KEV | %63,0 | 10 Tem 2025 |
49Planlayın | CVE-2025-62168Kavram kanıtı | Squid vulnerable to information disclosure via authentication credential leakage in error handlingsquid-cache · squid · CWE-209 | Yüksek7,5 | — | %63,4 | 17 Eki 2025 |
45Planlayın | CVE-2010-3332Kavram kanıtı | Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servimicrosoft · .net framework · CWE-209 | Orta6,4 | — | %68,2 | 22 Eyl 2010 |
40Planlayın | CVE-2018-11325İstismar yok | An issue was discovered in Joomla! Core before 3.8.8.joomla · joomla\! · CWE-209 | Kritik9,8 | — | %3,2 | 22 May 2018 |
40Planlayın | CVE-2019-7612İstismar yok | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.elastic · logstash · CWE-209 | Kritik9,8 | — | %2,4 | 25 Mar 2019 |
40Planlayın | CVE-2017-7945İstismar yok | The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2paloaltonetworks · pan-os · CWE-209 | Kritik9,8 | — | %1,8 | 28 Nis 2017 |
40Planlayın | CVE-2019-7644İstismar yok | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT sauth0 · auth0-wcf-service-jwt · CWE-209 | Kritik9,8 | — | %1,7 | 11 Nis 2019 |
39İzleyin | CVE-2018-14925İstismar yok | Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.matera · banco · CWE-209 | Kritik9,8 | — | %1,5 | 3 Ağu 2018 |
39İzleyin | CVE-2017-7551İstismar yok | 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different returfedoraproject · 389 directory server · CWE-209 | Kritik9,8 | — | %1,4 | 16 Ağu 2017 |
39İzleyin | CVE-2023-40763İstismar yok | User enumeration is found in PHPJabbers Taxi Booking Script v2.0.phpjabbers · taxi booking script · CWE-209 | Kritik9,8 | — | %1,1 | 28 Ağu 2023 |
39İzleyin | CVE-2021-42777İstismar yok | Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macstimulsoft · reports · CWE-209 | Kritik9,8 | — | %1,0 | 29 Eki 2022 |
39İzleyin | CVE-2023-40759İstismar yok | User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.phpjabbers · restaurant booking script · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40767İstismar yok | User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.phpjabbers · make an offer widget · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40760İstismar yok | User enumeration is found in PHP Jabbers Hotel Booking System v4.0.phpjabbers · hotel booking system · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40761İstismar yok | User enumeration is found in PHPJabbers Yacht Listing Script v2.0.phpjabbers · yacht listing script · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40762İstismar yok | User enumeration is found in PHPJabbers Fundraising Script v1.0.phpjabbers · fundraising script · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40764İstismar yok | User enumeration is found in PHP Jabbers Car Rental Script v3.0.phpjabbers · car rental script · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40766İstismar yok | User enumeration is found in in PHPJabbers Ticket Support Script v3.2.phpjabbers · ticket support script · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40765İstismar yok | User enumeration is found in PHPJabbers Event Booking Calendar v4.0.phpjabbers · event booking calendar · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40757İstismar yok | User enumeration is found in PHPJabbers Food Delivery Script v3.1.phpjabbers · food delivery script · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2023-40758İstismar yok | User enumeration is found in PHPJabbers Document Creator v1.0.phpjabbers · document creator · CWE-209 | Kritik9,8 | — | %0,9 | 28 Ağu 2023 |
39İzleyin | CVE-2024-28285İstismar yok | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reCWE-209 | Kritik9,8 | — | %0,5 | 14 May 2024 |
39İzleyin | CVE-2025-59872İstismar yok | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,hcltech · zie for web · CWE-209 | Kritik9,8 | — | %0,5 | 17 Haz 2026 |
- CVE-2024-2905990Hemen
.NET Framework Information Disclosure Vulnerability
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %99microsoft · .net framework22 Mar 2024
- CVE-2013-733171Bu hafta
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathna
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %50microsoft · internet explorer26 Şub 2014
- CVE-2025-4781366Bu hafta
loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a long value in the UI
OrtaCVSS 4,3KEVSilahlaştırılmışEPSS %63wftpserver · wing ftp server10 Tem 2025
- CVE-2025-6216849Planlayın
Squid vulnerable to information disclosure via authentication credential leakage in error handling
YüksekCVSS 7,5Kavram kanıtıEPSS %63squid-cache · squid17 Eki 2025
- CVE-2010-333245Planlayın
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Servi
OrtaCVSS 6,4Kavram kanıtıEPSS %68microsoft · .net framework22 Eyl 2010
- CVE-2018-1132540Planlayın
An issue was discovered in Joomla! Core before 3.8.8.
KritikCVSS 9,8İstismar yokEPSS %3joomla · joomla\!22 May 2018
- CVE-2019-761240Planlayın
A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs.
KritikCVSS 9,8İstismar yokEPSS %2elastic · logstash25 Mar 2019
- CVE-2017-794540Planlayın
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2
KritikCVSS 9,8İstismar yokEPSS %2paloaltonetworks · pan-os28 Nis 2017
- CVE-2019-764440Planlayın
Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT s
KritikCVSS 9,8İstismar yokEPSS %2auth0 · auth0-wcf-service-jwt11 Nis 2019
- CVE-2018-1492539İzleyin
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components.
KritikCVSS 9,8İstismar yokEPSS %2matera · banco3 Ağu 2018
- CVE-2017-755139İzleyin
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different retur
KritikCVSS 9,8İstismar yokEPSS %1fedoraproject · 389 directory server16 Ağu 2017
- CVE-2023-4076339İzleyin
User enumeration is found in PHPJabbers Taxi Booking Script v2.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · taxi booking script28 Ağu 2023
- CVE-2021-4277739İzleyin
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any mac
KritikCVSS 9,8İstismar yokEPSS %1stimulsoft · reports29 Eki 2022
- CVE-2023-4075939İzleyin
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · restaurant booking script28 Ağu 2023
- CVE-2023-4076739İzleyin
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · make an offer widget28 Ağu 2023
- CVE-2023-4076039İzleyin
User enumeration is found in PHP Jabbers Hotel Booking System v4.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · hotel booking system28 Ağu 2023
- CVE-2023-4076139İzleyin
User enumeration is found in PHPJabbers Yacht Listing Script v2.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · yacht listing script28 Ağu 2023
- CVE-2023-4076239İzleyin
User enumeration is found in PHPJabbers Fundraising Script v1.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · fundraising script28 Ağu 2023
- CVE-2023-4076439İzleyin
User enumeration is found in PHP Jabbers Car Rental Script v3.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · car rental script28 Ağu 2023
- CVE-2023-4076639İzleyin
User enumeration is found in in PHPJabbers Ticket Support Script v3.2.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · ticket support script28 Ağu 2023
- CVE-2023-4076539İzleyin
User enumeration is found in PHPJabbers Event Booking Calendar v4.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · event booking calendar28 Ağu 2023
- CVE-2023-4075739İzleyin
User enumeration is found in PHPJabbers Food Delivery Script v3.1.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · food delivery script28 Ağu 2023
- CVE-2023-4075839İzleyin
User enumeration is found in PHPJabbers Document Creator v1.0.
KritikCVSS 9,8İstismar yokEPSS %1phpjabbers · document creator28 Ağu 2023
- CVE-2024-2828539İzleyin
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re
KritikCVSS 9,8İstismar yokEPSS %114 May 2024
- CVE-2025-5987239İzleyin
HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,
KritikCVSS 9,8İstismar yokEPSS %0hcltech · zie for web17 Haz 2026