Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-209

MITRE ↗

CWE-209

27
CRITICAL
74
HIGH
394
MEDIUM
84
LOW
596 CVEs · Page 4/12
5.3
CVE-2025-41441

Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unau

5.3
CVE-2024-37524

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain sensitive information when a de

5.3
CVE-2025-54791

OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when rese

5.3
CVE-2025-52619

HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, err

5.3
CVE-2025-9229

Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated att

5.3
CVE-2025-43777

Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024

5.3
CVE-2025-54291

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remo

5.3
CVE-2025-62397

The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially

5.3
CVE-2025-12365

Error Messages Wrapped In HTTP Header.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

5.3
CVE-2025-61959

Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebR

5.3
CVE-2025-9122

Hitachi Vantara Pentaho Data Integration and Analytics Community Dashboard Framework prior to versions 10.2.0.4, includi

5.0
CVE-2025-48562

In writeContent of RemotePrintDocument.java, there is a possible information disclosure due to a logic error. This could

4.9
CVE-2025-46575

There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages

4.5
CVE-2025-4166

Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in

4.4
CVE-2024-12380

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting f

4.3
CVE-2024-5591

IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detaile

4.3
CVE-2022-22363

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive

4.3
CVE-2024-25037

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive

4.3
CVE-2024-35111

IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic

4.3
CVE-2024-49798

IBM ApplinX 11.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message i

4.3
CVE-2025-0279

HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal

4.3
CVE-2025-32238

Generation of Error Message Containing Sensitive Information vulnerability in vcita Online Booking & Scheduling Calendar

4.3
CVE-2025-25045

IBM InfoSphere Information 11.7 Server authenticated user to obtain sensitive information when a detailed technical erro

4.3
CVE-2025-25025

IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error

4.3
CVE-2024-56342

IBM Verify Identity Access Digital Credentials 24.06 could allow a remote attacker to obtain sensitive information when

4.3
CVE-2025-36090

IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could allow a remote attacker to obtain information about the applicati

4.3
CVE-2025-47813 KEV

loginok.html in Wing FTP Server before 7.4.4 discloses the full local installation path of the application when using a

4.3
CVE-2025-8852

A vulnerability was identified in WuKongOpenSource WukongCRM 11.0. This affects an unknown part of the file /adminFile/u

4.3
CVE-2025-59016

Error messages containing sensitive information in the File Abstraction Layer in TYPO3 CMS versions 9.0.0-9.5.54, 10.0.0

4.3
CVE-2025-64749

Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messa

4.3
CVE-2025-54562

A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows

4.3
CVE-2025-52671

Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes

4.3
CVE-2025-36437

IBM Planning Analytics Local 2.1.0 - 2.1.15 could disclose sensitive information about server architecture that could ai

4.3
CVE-2025-13978

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 1

4.1
CVE-2025-23185

Due to improper error handling in SAP Business Objects Business Intelligence Platform, technical details of the applicat

4.0
CVE-2025-49128

Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr

3.7
CVE-2021-20455

IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive

3.7
CVE-2025-8548

A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function send

3.7
CVE-2025-9005

A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The ma

3.5
CVE-2024-52611

The SolarWinds Platform is vulnerable to an information disclosure vulnerability through an error message. While the dat

3.5
CVE-2025-0049

When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error

3.5
CVE-2024-41983

A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Au

3.5
CVE-2025-31998

HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information.

3.3
CVE-2024-56467

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56493

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56494

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56495

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56496

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56810

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

3.3
CVE-2024-56811

IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is ret

Frequently Asked Questions

What is CWE-209?

CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-209?

There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.

How can I protect against CWE-209 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.

Detect CWE-209 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.

Get Started