Vulnerabilities (CVE)

Filtered by CWE-209
Total 477 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-23216 1 Argoproj 1 Argo Cd 2025-06-06 N/A 6.8 MEDIUM
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A vulnerability was discovered in Argo CD that exposed secret values in error messages and the diff view when an invalid Kubernetes Secret resource was synced from a repository. The vulnerability assumes the user has write access to the repository and can exploit it, either intentionally or unintentionally, by committing an invalid Secret to repository and triggering a Sync. Once exploited, any user with read access to Argo CD can view the exposed secret data. The vulnerability is fixed in v2.13.4, v2.12.10, and v2.11.13.
CVE-2024-22646 1 Seopanel 1 Seo Panel 2025-06-04 N/A 5.3 MEDIUM
An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allows an attacker to guess which emails exist on the system.
CVE-2025-25025 1 Ibm 1 Security Guardium 2025-06-04 N/A 4.3 MEDIUM
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVE-2025-41441 1 Synck 1 Mailform Pro Cgi 2025-06-03 N/A 5.3 MEDIUM
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
CVE-2024-23689 1 Clickhouse 1 Java Libraries 2025-05-30 N/A 8.8 HIGH
Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.
CVE-2025-40653 2025-05-28 N/A N/A
User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a difference in error messages could allow an attacker to determine whether a username is valid or not, allowing a brute force attack on valid usernames.
CVE-2022-2760 1 Octopus 1 Octopus Server 2025-05-21 N/A 4.3 MEDIUM
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.
CVE-2025-31141 1 Jetbrains 1 Teamcity 2025-05-16 N/A 2.7 LOW
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page
CVE-2025-22218 1 Vmware 2 Aria Operations For Logs, Cloud Foundation 2025-05-14 N/A 8.5 HIGH
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
CVE-2021-29040 1 Liferay 2 Digital Experience Platform, Liferay Portal 2025-05-13 5.0 MEDIUM 5.3 MEDIUM
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.
CVE-2024-39719 1 Ollama 1 Ollama 2025-05-13 N/A 7.5 HIGH
An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that does not exist, it reflects the "File does not exist" error message to the attacker, providing a primitive for file existence on the server.
CVE-2025-46575 1 Zte 1 Zxcloud Goldendb 2025-05-12 N/A 4.9 MEDIUM
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
CVE-2025-46746 2025-05-12 N/A 5.8 MEDIUM
An administrator could discover another account's credentials.
CVE-2024-32046 1 Mattermost 1 Mattermost Server 2025-05-12 N/A 4.3 MEDIUM
Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error messages in API requests even if the developer mode is off which allows an attacker to get information about the server such as the full path were files are stored
CVE-2025-0049 1 Fortra 1 Goanywhere Managed File Transfer 2025-05-10 N/A 3.5 LOW
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
CVE-2022-2508 1 Octopus 1 Octopus Server 2025-05-07 N/A 5.3 MEDIUM
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.
CVE-2021-42777 1 Stimulsoft 1 Reports 2025-05-07 N/A 9.8 CRITICAL
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start.
CVE-2022-40292 1 Phppointofsale 1 Php Point Of Sale 2025-05-06 N/A 5.3 MEDIUM
The application allowed for Unauthenticated User Enumeration by interacting with an unsecured endpoint to retrieve information on each account within the system.
CVE-2021-44155 1 Reprisesoftware 1 Reprise License Manager 2025-04-30 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response if a username is valid includes Login Failed, but does not include this string if the username is invalid. This allows an attacker to enumerate valid users.
CVE-2024-45440 1 Drupal 1 Drupal 2025-04-21 N/A 5.3 MEDIUM
core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash_salt is file_get_contents of a file that does not exist.