vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid i
Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technolog
Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP
MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload
XenForo before 2.3.7 discloses filesystem paths through exception messages triggered by open_basedir restrictions. This
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apach
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and belo
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.ph
Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the
Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to vali
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt f
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that return
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by inc
monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF)
Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base:
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,
A vulnerability in update-reports-purge-settings.sh script logging for Brocade SANnav before 2.4.0a could allow the coll
Vulnerabilities in the API error handling of an HPE Aruba Networking 5G Core server API could allow an unauthenticated
When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operat
llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose
OpenClaw is a personal AI assistant. Prior to version 2026.2.15, in some shared-agent deployments, OpenClaw session tool
The Fancy Product Designer plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includi
A vulnerability was identified in birkir prime up to 0.4.0.beta.0. This impacts an unknown function of the file /graphql
Moonraker is a Python web server providing API access to Klipper 3D printing firmware. In versions 0.9.3 and below, inst
A vulnerability in the PHP backend of gemsloyalty.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers
A vulnerability in the PHP backend of gemscms.aptsys.com.sg thru 2025-05-28 allows unauthenticated remote attackers to t
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode
IBM Cloud Pak System displays sensitive information in user messages that could aid in further attacks against the syste
IBM Cloud Pak System is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScrip
IBM Cloud Pak System does not set the secure attribute on authorization tokens or session cookies. Attackers may be able
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. Detailed messages are displayed
free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core
free5GC is an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 of th
free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core
OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacke
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.
Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1.
A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enum
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its repor
Vvveb before version 1.0.8.2 contains an information disclosure vulnerability that allows unauthenticated attackers to o
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns fu
IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote at
A flaw was found in Keycloak. A remote, unauthenticated attacker can exploit this vulnerability by sending specially cra
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 109 CVE records associated with CWE-209 in our database. Of these, 1 are critical severity, 15 are high severity, and 61 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started