Falhas do tipo CWE-209

371 resultados
CVE-2020-25633MEDIUMA flaw was found in RESTEasy client in all versions of RESTEasy up to 4.5.6.Final. It may allow client users to obtain the server's potentiaEPSS 1.2%CVE-2022-31140HIGHValinor error messages leading to potential data exfiltrationEPSS 1.2%CVE-2020-5274MEDIUMExceptions displayed in non-debug configurations in SymfonyEPSS 1.2%CVE-2021-3393An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but EPSS 1.2%CVE-2019-5483Seneca < 3.9.0 contains a vulnerability that could lead to exposing environment variables to unauthorized users.EPSS 1.2%CVE-2019-11252MEDIUMCredential leakage when failing to mountEPSS 1.1%CVE-2022-0504MEDIUMGeneration of Error Message Containing Sensitive Information in microweber/microweberEPSS 1.1%CVE-2020-15132MEDIUMReset Password / Login vulnerability in SuluEPSS 1.1%CVE-2020-8213An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid uEPSS 1.1%CVE-2019-19342MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and the password containEPSS 1.1%CVE-2021-26726HIGHRemote code execution in Valmet DNA before Collection 2021EPSS 1.1%CVE-2019-3756MEDIUMRSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend databasEPSS 1.1%CVE-2022-31124HIGHPossible leak of key's raw field if declared length is incorrect in openssh_key_parserEPSS 1.0%CVE-2021-32937HIGHMDT AutoSave Generation of Error Message Containing Sensitive InformationEPSS 1.0%CVE-2023-31286MEDIUMAn issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks thEPSS 1.0%CVE-2022-0622MEDIUMGeneration of Error Message Containing Sensitive Information in snipe/snipe-itEPSS 1.0%CVE-2024-27315MEDIUMApache Superset: Improper error handling on alertsEPSS 1.0%CVE-2022-0079MEDIUMGeneration of Error Message Containing Sensitive Information in star7th/showdocEPSS 1.0%CVE-2021-42777CRITICALStimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any macEPSS 1.0%CVE-2021-4177MEDIUMGeneration of Error Message Containing Sensitive Information in livehelperchat/livehelperchatEPSS 0.9%