CVE & CISA-KEV Catalog

403,870 CVEs1,740 actively exploited (KEV)

Want to know which of these are on your machines? Scan your endpoints with the free CVE scanner, 200 endpoints free.

Active:
  • CVSS 5.3 v3·EPSS -·No fix yet

    pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. Version

    Published 2026-10-09

  • CVSS 3.7 v3·EPSS 0.2%·No fix yet

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information exposure.

    Published 2026-10-09

  • CVSS 6.3 v4·EPSS 0.3%·No fix yet

    Parse Server 8.2.2 before 8.6.92 and 9.0.0 before 9.10.1-alpha.12 contains an information disclosure vulnerability in which GraphQL validation error messages reveal hidden class names when public introspection is disabled. Unauthenticated attackers holding only the public Application Id can send crafted operations triggering unknown-argument or invalid enum value errors to learn pointer and relation target classes.

    Published 2026-10-08

  • CVSS 4.3 v3·EPSS 0.2%·No fix yet

    Gitea's repository migration and pull mirror egress checks could be bypassed with a hostname that returns multiple DNS answers, because the address that was validated was not necessarily the address Git later connected to. A low-privileged user who can create migrations or mirrors could direct the server to internal services, reading from and writing to reachable internal Git or HTTP endpoints. Content from internal responses could additionally be disclosed through migration and mirror error messages.

    Published 2026-10-06

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    A security vulnerability has been detected in uptrace up to 2.1.0-beta.8. Affected by this vulnerability is the function Login of the file pkg/org/user_handler.go. The manipulation leads to information exposure through error message. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published 2026-10-06

  • CVSS 3.7 v3·EPSS 0.2%·No fix yet

    HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.

    Published 2026-10-01

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.

    Published 2026-10-01

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.

    Published 2026-10-01

  • CVSS 3.1 v3·EPSS 0.2%·No fix yet

    iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.

    Published 2026-10-01

  • CVSS 5.4 v3·EPSS 0.2%·No fix yet

    JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a lo

    Published 2026-09-29

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file locations in error responses. Unauthenticated attackers can distinguish between registered and unregistered email addresses by comparing error location fields returned from POST /api/auth/session/login requests.

    Published 2026-09-26

  • CVSS 7.1 v4·EPSS 0.3%·No fix yet

    PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that includes the offending parameter value in plaintext. PRTG provides a documented placeholder variable, %windowspassword, which resolves to the configured Windows/domain password used by PRTG and can be passed as a sensor parameter. Any PRTG user who is not restricted to read-only access and is permitted to create sensors (the default for non-read-only users) can pass %windowspassword as an argument to the demo VBScript sensor, triggering the type-mismatch error and causing PRTG to display the plaintext password in the sensor's error output.

    Published 2026-09-24

  • CVSS 7.7 v3·EPSS 0.4%·Fix available

    A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes its plaintext value in the minimum/maximum length validation error message returned in the HTTP response. A user with the delegated JobTemplate Admin role can tighten the survey length constraint and trigger revalidation of a schedule or node created by another, higher-privileged user, thereby recovering that user's stored password in plaintext.

    Published 2026-09-23

  • CVSS 2.7 v3·EPSS 0.3%·Fix available

    Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the test-render (stub has small job.id). At runtime, the gated branch executes and exceptions write full tracebacks into notification body, which is POSTed to attacker-controlled webhook URL. Leaks install paths, Python version, source line numbers.

    Published 2026-09-23

  • CVSS 4.3 v3·EPSS 0.2%·No fix yet

    HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.

    Published 2026-09-23

  • CVSS 2.7 v3·EPSS 0.2%·No fix yet

    IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published 2026-09-23

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published 2026-09-23

  • CVSS 5.3 v3·EPSS 0.4%·No fix yet

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The detail=str(e), detail=str(exc), and equivalent formatted-message paths expose server filesystem paths, database host, port, user, and database names, language-model provider diagnostics, configuration details, and Python library internals to a network client that can trigger an error. The default unauthenticated configuration makes those responses reachable without credentials, and URI-configured backends can disclose connection strings containing credentials depending on the underlying driver error. This issue is fixed in version 1.5

    Published 2026-09-22

  • CVSS 6.2 v3·EPSS 0.1%·No fix yet

    CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

    Published 2026-09-21

  • CVSS 4.3 v3·EPSS 0.2%·No fix yet

    IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.

    Published 2026-09-18

  • CVSS 5.3 v3·EPSS 0.2%·No fix yet

    IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

    Published 2026-09-18

  • CVSS 2.7 v3·EPSS 0.5%·No fix yet

    Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions without validating it as a version. An authenticated Operator can submit traversal segments in TalosVersion, and url.URL.JoinPath normalizes them into unintended paths on the configured image-factory host. Omni then issues HTTP GET requests to those paths and reflects error-body content, enabling same-host endpoint probing and possible disclosure of internal diagnostics while preventing redirection to another host or write requests. This issue is fixed in versions 1.6.6 and 1.7.3.

    Published 2026-09-17

  • CVSS 5.8 v3·EPSS 0.5%·Fix available

    vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling eval with malformed source) and then read the error's .stack property; the bridge forwards the .stack read to the host-realm formatter, bypassing the sandbox-side host-path redaction introduced for GHSA-v27g-jcqj-v8rw. The returned stack string discloses absolute paths from vm2, Node.js internals, and the embedding application's own source tree, along with host function names. Default new VM() and new NodeVM() configurations are affected without any special options, and the issue persists when string eval is disabled because the host-side transformer throws b

    Published 2026-09-17

  • CVSS 5.3 v3·EPSS 0.4%·No fix yet

    canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing access logs, proxy logs, and APM traces to persist the credentials in plaintext. When a token request fails, OAuth2::obtainAccessToken() also passes the credential-bearing Guzzle request URI into AuthorizationFailedException, so application logs and error trackers can record the same secrets. An attacker with access to affected telemetry can obtain Canto credentials and use them to request access tokens for the tenant. This issue is fixed in version 3.0.0.

    Published 2026-09-15

  • CVSS 6.2 v3·EPSS 0.2%·No fix yet

    MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client, including an LLM agent induced to call the tool, can use ../ traversal or an absolute path to target any file readable by the server process. A valid JSON file is parsed and imported into the caller's session, allowing its full contents to be retrieved through context_get or context_export, while JSON.parse errors for non-JSON files can return leading file bytes in a SyntaxError message. The two disclosure modes can expose other exported sessions, JSON credentials or service-account files, environment files, and portio

    Published 2026-09-15

  • CVSS 5.8 v4·EPSS 0.2%·No fix yet

    hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain the X-Vault-Token request header and err.config.data request body, including submitted passwords or secret values. When a consuming application records the caught exception through console logging, structured loggers, monitoring, crash reporting, or an application performance monitoring service, the live Vault token and request secrets can be stored in plaintext and exposed to anyone with access to that output. A stolen token can permit unauthorized access to the Vault instance

    Published 2026-09-14

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.7 v3·EPSS 0.9%·Fix available

    Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 5.5 v3·EPSS 0.5%·Fix available

    Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 1.0%·Fix available

    Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 0.9%·No fix yet

    Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

    Published 2026-09-08

  • CVSS 6.5 v3·EPSS 0.3%·No fix yet

    An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating a log-amplification resource exhaustion vector (disk growth and I/O contention) without requiring authentication.

    Published 2026-09-01

  • CVSS 2.1 v4·EPSS 0.2%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value of a confirmed field to an actor who fails its confirmation check. Ash.Resource.Validation.Confirm's atomic implementation (atomic/2 in lib/ash/resource/validation/confirm.ex) built the mismatch error with its value set to the field being confirmed. When the actor supplies only the confirmation argument and not the field itself, value resolves through atomic_ref/2 to the field's current stored value, so the mismatch error echoes that stored value back to the actor. Against a confirmation guarding a sensitive attribute, an actor can submit a deliberately wrong confirmation and read the real value from the returned error. The fix reports the actor-supplied confirmation in

    Published 2026-09-01

  • CVSS 6.3 v4·EPSS 0.5%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to read internal application data from an HTTP 500 response body. When a typed-controller route handler returns anything other than a %Plug.Conn{}, dispatch/3 in lib/ash_typescript/typed_controller/request_handler.ex passes the value to unexpected_return/2, which interpolates inspect(value, limit: 50) directly into the response message. The limit option bounds elements per collection rather than the term as a whole, so a handler falling through with a term such as {:error, %User{}} or a changeset serialises its full field set, including hashed passwords, tokens, and tenant identifiers, into the JSON error returned to the caller. This contradicts the

    Published 2026-09-01

  • CVSS 6.3 v4·EPSS 0.5%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_typescript allows an unauthenticated attacker to receive unredacted internal error data by provoking an error shape the configured error handler does not match. apply_error_handler/3 in lib/ash_typescript/rpc/errors.ex is the only hook an application has for redacting or suppressing errors before they reach the client, with a nil return dropping the error entirely. Its rescue clause logs a warning and then returns the original, pre-handler error map. Error handlers are conventionally written as pattern-matching functions over expected error shapes, so an unmatched shape raises FunctionClauseError and the raw transformed error, including any secrets carried in vars, is emitted instead. An intent t

    Published 2026-09-01

  • CVSS 2.3 v4·EPSS 0.5%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, crash reports and the dev error page. When AshPhoenix.Form.Auto builds a union sub-form and the submitted _union_type does not match a configured type, both raise sites built the message with inspect(params, pretty: true), embedding the full untrusted param map, and also inspected the internal union constraints[:types]. Because the message is constructed by the library rather than Phoenix's parameter logger, config :phoenix, :filter_parameters never redacts it. An attacker controls both the trigger and the contents: submitting %{"_union_type" => "nope", "p

    Published 2026-08-31

  • CVSS 5.3 v4·EPSS 0.5%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No filtering happened first, so anything raised inside a tool callback or lifecycle hook (database constraint messages, adapter errors, query fragments, policy or validation internals) was echoed as-is. A chat user who can steer tool arguments into a raising code path receives the raw internal text. The fix routes raised tool errors throu

    Published 2026-08-31

  • CVSS 7.1 v4·EPSS 0.5%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChanges in the :invalid class, which AshJsonApi and AshGraphql render back to the caller. The embedding client's error term is not sanitized, so it can carry the request URL, the provider response body, and, for HTTP clients that keep the request in the error struct, the outbound Authorization header with the provider API key. Failures are a

    Published 2026-08-31

  • CVSS 6.9 v4·EPSS 0.5%·No fix yet

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_graphql allows a remote client to read internal field names that an application configured its error_handler to redact. In AshGraphql.Errors, each error is passed to the configured error_handler and the returned map is merged with the pre-handler path via Map.put_new(handled, :path, path). Because put_new defers to the handler only when the handler itself set :path, a sanitizing handler that returns a fresh map or deletes :path has that decision reverted. The re-injected path comes from build_error_path/5, which falls back to raw internal Ash attribute and argument names when no field_names mapping is configured. A validation failure on a non-exposed or nested field therefore returns internal nam

    Published 2026-08-30

  • CVSS 5.3 v3·EPSS 0.3%·Fix available

    When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

    Published 2026-08-27

  • CVSS 7.5 v3·EPSS 0.4%·Fix available

    A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

    Published 2026-08-27

  • CVSS 3.9 v3·EPSS 0.1%·No fix yet

    HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.

    Published 2026-08-26

  • CVSS 2.7 v3·EPSS 0.3%·No fix yet

    rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

    Published 2026-08-25

  • CVSS 5.3 v3·EPSS 0.3%·No fix yet

    The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned MAC Addresses' function. Due to improper generation of error messages, an unauthenticated attacker with network access to the web interface can retrieve the logged MAC addresses via browser developer tools.

    Published 2026-08-24

  • CVSS 3.5 v3·EPSS 0.3%·No fix yet

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

    Published 2026-08-21

  • CVSS 6.5 v3·EPSS 0.5%·Fix available

    n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at the connection level, the node re-throws the underlying HTTP client error unchanged instead of wrapping it in n8n's standard error type. That error contains the live request's headers, including a decrypted credential secret, which the execution engine persists verbatim. Any authenticated user able to read the resulting execution can retrieve the decrypted credential secret from the stored run data.

    Published 2026-08-20

  • CVSS 5.3 v4·EPSS 0.5%·No fix yet

    Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw exception strings to authenticated Home Assistant users. Some exception messages could contain internal filesystem paths or implementation details. The disclosed information could help an authenticated user fingerprint a Home Assistant installation and refine follow-up attacks. This issue is fixed in version 2.5.2.

    Published 2026-08-18

  • CVSS 7.5 v3·EPSS 0.4%·Fix available

    openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.

    Published 2026-08-17

  • CVSS 3.7 v3·EPSS 0.4%·No fix yet

    CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response, or when an internal exception occurs, the caller receives verbatim upstream content and internal detail (hostnames, internal IPs, DB errors, stack fragments). This vulnerability is fixed in 0.4.112.

    Published 2026-08-14

Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.