CWE-209

CWE-209 · 10 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-209, highest CVSS first.

  1. HIGH 7.7CVE-2026-84499

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated again…

    AI risk analysis on Exploit-DB.ai →

  2. MEDIUM 5.8CVE-2026-92936public PoC

    vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed sourc…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.3CVE-2026-100677public PoC

    stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error responses. Unauthenticated attackers can distinguish between registered and unregistered email addresses by comparing error …

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.3CVE-2026-3626

    IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    concert · linux kernel

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.3CVE-2026-85709public PoC

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The …

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.3CVE-2026-47622public PoC

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

    dynamo · linux kernel

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 4.3CVE-2026-71461

    HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) o…

    AI risk analysis on Exploit-DB.ai →

  8. LOW 2.7CVE-2026-71463

    Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the test-render (stub has …

    AI risk analysis on Exploit-DB.ai →

  9. LOW 2.7CVE-2026-4921

    IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    AI risk analysis on Exploit-DB.ai →

  10. UNSCOREDCVE-2026-4638

    PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending …

    AI risk analysis on Exploit-DB.ai →