CWE-209

High likelihood

Generation of Error Message Containing Sensitive Information

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product generates an error message that includes sensitive information about its environment, users, or associated data.

580 vulnerabilities with CWE-209
CVE-2026-11904 MEDIUM
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 5.3
CVE-2026-59943 MEDIUM
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
CVE-2026-56537 LOW
HCL Connections is vulnerable to information disclosure
CVSS 3.5
CVE-2026-66009 MEDIUM
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
CVE-2026-66008 MEDIUM
Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages
CVE-2026-13182 HIGH
RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX
CVSS 7.5
CVE-2026-64627 MEDIUM
Parse Server 9.0.0 Schema Disclosure via GraphQL Variable Coercion
CVE-2026-63748 MEDIUM
SurrealDB before 3.1.0 Information Disclosure via Error Messages
CVSS 4.3
CVE-2026-8861 MEDIUM
Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access
CVSS 5.3
CVE-2026-56139 MEDIUM
Apache Camel Undertow - Stack Trace Information Disclosure
CVSS 5.3
CVE-2026-49365 MEDIUM
Apache Camel Netty HTTP - Stack Trace Information Disclosure
CVSS 5.3
CVE-2026-53906 HIGH
Mycomplianceoffice Mco < 25.3.3.1 - Path Traversal
CVSS 8.2
CVE-2026-56331 MEDIUM
Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Magic String
CVSS 5.3
CVE-2026-47775 MEDIUM
Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption
CVSS 6.8
CVE-2026-49979 LOW
Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter
CVSS 2.7
CVE-2026-47248 MEDIUM
Parse Server: GraphQL "Did you mean" validation suggestions disclose schema to unauthenticated callers
CVE-2026-40997 MEDIUM
SOAP security faults leak Spring Security account state
CVSS 5.3
CVE-2026-41730 MEDIUM
Spring Data REST exposes persistence-layer internals in error responses
CVSS 5.3
CVE-2026-9794 MEDIUM
Keycloak: keycloak: information disclosure via saml ecp endpoint
CVSS 5.3
CVE-2026-42459 HIGH
free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive Information in github.com/free5gc/udm
CVSS 7.5
CVE-2026-1248 MEDIUM
IBM Business Automation Workflow information leak
CVSS 4.3
CVE-2026-9583 MEDIUM
SourceCodester CET Automated Grading System with AI Predictive Analytics SQL index.php information exposure
CVSS 4.3
CVE-2026-45728 HIGH
Algernon: Single-file mode unconditionally enables debug mode
CVSS 7.5
CVE-2026-5511 LOW
Information Disclosure via Diagnostic Interface Due to Improper Input Validation on TP-Link's Archer AX72
CVSS 2.7
CVE-2026-7860 LOW
Possible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend Build
Details
Vulnerabilities 580
Exploit Likelihood High