VulnSea

CWE-209

CVEs classified under CWE-209, newest first.

50 CVEsRSS

GHSA-cc8f-fcx3-gpjrHigh· 7.7
3mo ago

SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter

SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter

Twilightsurrealdb · surrealdbvia GHSA
CVE-2026-40997Medium· 5.3
3mo ago

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with…

Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or callback outcomes, instead of failing with…

Sunlitbroadcom · spring_web_servicesEPSS 0.37%via NVD
CVE-2026-41730Medium· 5.3
3mo ago

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16…

Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16…

Sunlitvmware · spring_data_restEPSS 0.20%via NVD
CVE-2026-7860Low· 1.6
4mo ago

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status.…

A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status.…

Sunlitvaadin · com.vaadin:flow-plugin-baseEPSS 0.12%via NVD
CVE-2026-29146High· 7.5
5mo ago

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 thr…

Twilightapache · tomcatEPSS 8.8%via NVD
CVE-2025-14243Medium· 5.3
5mo ago

A flaw was found in the OpenShift Mirror Registry

A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account cre…

Sunlitredhat · mirror_registry_for_red_hat_openshiftEPSS 0.29%via NVD
CVE-2026-22778Critical· 9.8PoC
7mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a hea…

Abyssalvllm · vllmEPSS 3.8%via NVD
CVE-2025-1395High· 8.2
7mo ago

Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc

Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026.  NOTE: Th…

TwilightEPSS 0.31%via NVD
CVE-2025-11065Medium· 5.3
7mo ago

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode

A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input valu…

Sunlitgo-viper · github.com/go-viper/mapstructure/v2EPSS 0.37%via NVD
CVE-2025-52023Medium· 5.3
8mo ago

A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces

A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to trigger detailed error messages that disclose internal file paths, code snippets, and stack traces. This occurs when s…

Sunlitaptsys · gemscms_backendEPSS 0.45%via NVD
CVE-2026-20838Medium· 5.5
8mo ago

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

Sunlitmicrosoft · windows_11_23h2EPSS 0.67%via NVD
CVE-2025-8852Medium· 4.3
1y ago

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/upload of the component API Response Handler. The manipulation leads to information exposure through error message. It…

Sunlit5kcrm · wukong_crmEPSS 0.36%via NVD
CVE-2025-44203High· 7.5PoC
1y ago

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking

In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is completed and performs database creation without locking. By sending many concurrent requests, an attacker can trigger a…

Midnightdigitaldruid · hoteldruidEPSS 0.57%via NVD
CVE-2024-23689High· 8.8
2y ago

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificat…

Twilightclickhouse · java_librariesEPSS 0.68%via NVD
CVE-2023-0833Medium· 4.7
2y ago

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value

A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an authenticated atta…

Sunlitsquareup · okhttpEPSS 0.44%via NVD
CVE-2023-37306High· 7.5
3y ago

MISP 2.4.172 mishandles different certificate file extensions in server sync

MISP 2.4.172 mishandles different certificate file extensions in server sync. An attacker can obtain sensitive information because of the nature of the error messages.

Twilightmisp-project · mispEPSS 0.53%via NVD
CVE-2022-39307Medium· 5.3
3y ago

grafana: User enumeration via forget password (CVE-2022-39307)

An information leak was discovered in Grafana. Remote unauthenticated users could exploit the forget password feature to discover which user accounts exist.

SunlitRed Hat · Red Hat Enterprise Linux 8EPSS 0.75%via CSAF
CVE-2021-29040Medium· 5.3
5y ago

The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the cont…

The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the cont…

Sunlitliferay · digital_experience_platformEPSS 1.1%via NVD
CVE-2020-15666Medium· 6.5
5y ago

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message

When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerro…

Sunlitmozilla · firefoxEPSS 1.2%via NVD
CVE-2018-10624Medium· 4.3
8y ago

In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…

In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…

Sunlitjohnsoncontrols · bcproEPSS 0.80%via NVD
CWE-209 vulnerabilities (CVEs) — page 2 · VulnSea