Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti
Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. Wh
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote cl
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider requ
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal erro
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credential
ChurchCRM is an open-source church management system. Versions prior to 6.5.3 may disclose database information in an er
An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. There are verbose error messages.
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin
Information Exposure Through an Error Message vulnerability in Progress Software Corporation Sitefinity.This issue affec
In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is com
Improper error handling vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information whe
An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that
In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed ses
An issue has been discovered in GitLab EE affecting all versions from 17.1 before 17.8.7, 17.9 before 17.9.6, and 17.10
IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a
Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated
MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain te
An administrator could discover another account's credentials.
A flaw was found in Infinispan CLI. A sensitive password, decoded from a Base64-encoded Kubernetes secret, is processed
In contentDescForNotification of NotificationContentDescription.kt, there is a possible notification content leak throug
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose
Generation of error message containing sensitive information in Windows USB Video Driver allows an authorized attacker t
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly
IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed techn
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 th
IBM Concert Software 1.0.0, 1.0.1, 1.0.2, 1.0.2.1, and 1.0.3 could allow a remote attacker to obtain sensitive informa
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system inf
The 1003 Mortgage Application plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and incl
Generation of Error Message Containing Sensitive Information vulnerability in paytiumsupport Paytium paytium allows Retr
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7,
IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.3.6 iFix1, 2.3.3.6 iFix2, 2.3.3.7,
IBM Cloud Pak System 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, and 2.3.4.0 could disclose sensitive
IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical er
IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensiti
The AForms Eats plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.3.1.
The Actionwear products sync plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all vers
The WooODT Lite – Delivery & pickup date time location for WooCommerce plugin for WordPress is vulnerable to Full Path D
The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th
After attempting to upload a file that does not meet prerequisites, GMOD Apollo will respond with local path information
Generation of Error Message Containing Sensitive Information vulnerability in Hillstone Networks Hillstone Next Generati
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. From 3.2.0 until 3.2.4, exception messa
A vulnerability in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to enumerate LDAP user accounts
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started