Vulnerabilities (CVE)

Filtered by CWE-209
Total 557 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-0053 1 Sap 1 Sap Basis 2026-06-17 N/A 5.3 MEDIUM
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.
CVE-2025-0049 1 Fortra 1 Goanywhere Managed File Transfer 2026-06-17 N/A 3.5 LOW
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
CVE-2024-8571 1 Erjemin 1 Roll Cms 2026-06-17 2.7 LOW 3.5 LOW
A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. The manipulation leads to information exposure through error message. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
CVE-2024-7426 1 Peepso 1 Peepso 2026-06-17 N/A 5.3 MEDIUM
The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
CVE-2024-7415 1 Coffee2code 1 Remember Me Controls 2026-06-17 N/A 5.3 MEDIUM
The Remember Me Controls plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
CVE-2024-6984 1 Canonical 1 Juju 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other sensitive data or relation accessible to the local charm.
CVE-2024-6980 1 Bitdefender 1 Gravityzone 2026-06-17 N/A 9.8 CRITICAL
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.
CVE-2024-6613 1 Mozilla 2 Firefox, Thunderbird 2026-06-17 N/A 5.5 MEDIUM
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128.
CVE-2024-6551 1 Givewp 1 Givewp 2026-06-17 N/A 5.3 MEDIUM
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.15.1. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
CVE-2024-6544 1 Coffee2code 1 Custom Post Limits 2026-06-17 N/A 5.3 MEDIUM
The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
CVE-2024-5591 3 Ibm, Linux, Microsoft 3 Jazz Foundation, Linux Kernel, Windows 2026-06-17 N/A 4.3 MEDIUM
IBM Jazz Foundation 7.0.2, 7.0.3, and 7.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
CVE-2024-5435 1 Gitlab 1 Gitlab 2026-06-17 N/A 4.5 MEDIUM
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions starting from 17.3 before 17.3.2 will disclose user password from repository mirror configuration.
CVE-2024-5250 1 Perforce 1 Akana Api 2026-06-17 N/A 3.5 LOW
In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations
CVE-2024-56812 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56811 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56810 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56496 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56495 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56494 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56493 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2026-06-17 N/A 3.3 LOW
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.