A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid
Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows
Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavatio
Sentry is an error tracking and performance monitoring platform. Version 24.11.0, and only version 24.11.0, is vulnerabl
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Sup
Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allow
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 could allow a remote attacker to obtain se
SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been
HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed erro
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all ve
An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially cr
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error mes
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enume
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec
Umbraco is an ASP.NET CMS. Some endpoints in the Management API can return stack trace information, even when Umbraco is
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint.
A vulnerability in janeczku/calibre-web allows unauthorized users to view the names of private shelves belonging to othe
A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' na
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensi
zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers
IBM Sterling Partner Engagement Manager 6.2.2 could allow a local attacker to obtain sensitive information when a detail
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a st
github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request an
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information t
An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK al
In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations
A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as
In the Linux kernel, the following vulnerability has been resolved: btrfs: send: handle path ref underflow in header it
HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error me
When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message c
IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive information when a detailed techn
The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected
User enumeration is found in PHPJabbers Food Delivery Script v3.1. This issue occurs during password recovery, where a d
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a diffe
User enumeration is found in PHP Jabbers Restaurant Booking Script v3.0. This issue occurs during password recovery, whe
User enumeration is found in PHP Jabbers Hotel Booking System v4.0. This issue occurs during password recovery, where a
User enumeration is found in PHPJabbers Yacht Listing Script v2.0. This issue occurs during password recovery, where a d
User enumeration is found in PHPJabbers Fundraising Script v1.0. This issue occurs during password recovery, where a dif
User enumeration is found in PHPJabbers Taxi Booking Script v2.0. This issue occurs during password recovery, where a di
User enumeration is found in PHP Jabbers Car Rental Script v3.0. This issue occurs during password recovery, where a dif
User enumeration is found in PHPJabbers Event Booking Calendar v4.0. This issue occurs during password recovery, where a
User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where
User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where
Dispatch is an open source security incident management tool. The server response includes the JWT Secret Key used for s
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical applica
league/oauth2-server is an implementation of an OAuth 2.0 authorization server written in PHP. Starting in version 8.3.2
Credential disclosure in the '/webs/userpasswd.htm' endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.4 an
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration
Frequently Asked Questions
What is CWE-209?
CWE-209 (CWE-209) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-209?
There are 697 CVE records associated with CWE-209 in our database. Of these, 27 are critical severity, 74 are high severity, and 394 are medium severity.
How can I protect against CWE-209 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-209 using AI-powered security agents.
Detect CWE-209 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-209 vulnerabilities across your infrastructure.
Get Started