CWE-209

High likelihood

Generation of Error Message Containing Sensitive Information

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product generates an error message that includes sensitive information about its environment, users, or associated data.

580 vulnerabilities with CWE-209
CVE-2026-22052 MEDIUM
NetApp ONTAP >= 9.12.1 - Authenticated Information Disclosure via S3 NAS Bucket Directory Listing
CVSS 4.3
CVE-2026-27643 MEDIUM
free5GC UDR <=1.4.1 - Info Disclosure
CVSS 5.3
CVE-2026-27004 MEDIUM
OpenClaw <2026.2.15 - Privilege Escalation
CVSS 5.5
CVE-2026-23598 MEDIUM
HPE Aruba 5G Core - Info Disclosure
CVSS 6.5
CVE-2026-22778 CRITICAL
vLLM 0.8.3-0.14.0 - Information Disclosure via Multimodal Endpoint Error Handling
CVSS 9.8
CVE-2026-24130 MEDIUM
Moonraker < 0.10.0 - LDAP Injection via Login Endpoint
CVSS 5.3
CVE-2026-1175 MEDIUM
birkir prime < 0.4.0 - Information Exposure via GraphQL Directive Handler Error Message
CVSS 5.3
CVE-2026-22646 MEDIUM
SICK incoming_goods_suite < 1.2.1 - Information Disclosure via Error Message
CVSS 4.3
CVE-2026-20838 MEDIUM
Windows Kernel - Information Disclosure via Error Message
CVSS 5.5
CVE-2025-59177 MEDIUM
Ericsson Packet Core Controller (PCC) - Generation of Error Message Containing Sensitive Information Vulnerability
CVE-2025-36328 MEDIUM
Error Message Containing Sensitive Information found in Watson Data Intelligence
CVSS 4.3
CVE-2025-59872 MEDIUM
HCL ZIE for Web 16.0 - Unrestricted File Upload
CVSS 4.3
CVE-2025-52611 LOW
HCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerability
CVSS 3.1
CVE-2025-52606 MEDIUM
HCL iControl - Weak Input Validation
CVSS 4.3
CVE-2025-31960 MEDIUM
HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
CVSS 5.3
CVE-2025-59853 LOW
HCL DFXAnalytics is affected by an Improper Error Handling vulnerability
CVSS 3.1
CVE-2025-52641 LOW
Internal Filesystem Exploration vulnerability
CVSS 2.9
CVE-2025-14243 MEDIUM
Mirror-registry: openshift mirror registry: user enumeration via authentication error messages
CVSS 5.3
CVE-2025-71282 HIGH
XenForo Path Disclosure via open_basedir Exceptions
CVSS 7.5
CVE-2025-13726 MEDIUM
IBM Sterling Partner Engagement Manager 6.2.3.0-6.2.3.5/6.2.4.0-6.2.4.2 - Info Disclosure
CVSS 5.3
CVE-2025-69253 MEDIUM
free5GC UDR <=1.4.1 - Info Disclosure
CVSS 5.3
CVE-2025-69208 MEDIUM
free5GC UDR <1.4.1 - Info Disclosure
CVSS 5.3
CVE-2025-65995 MEDIUM
Airflow <3.1.4/2.11.1 - Info Disclosure
CVSS 6.5
CVE-2025-36348 MEDIUM
IBM Sterling B2B Integrator - Info Disclosure
CVSS 4.9
CVE-2025-66594 MEDIUM
Yokogawa Electric Corporation - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 580
Exploit Likelihood High