The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.
Volume of CVEs assigned to CWE-1295 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48797CRITICAL Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane wi | Jun 16, 2026 | 9.3 | 34 | NO | NO |
CVE-2024-45784HIGH Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintention | Nov 15, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-38516HIGH ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched | Jun 25, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-4215HIGH Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials. | Oct 17, 2023 | 7.5 | 22 | NO | NO |
CVE-2025-12910MEDIUM Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain potentially sensitive information via debug logs. (Chromium secu | Nov 8, 2025 | 6.2 | 21 | NO | NO |
CVE-2025-42604MEDIUM This vulnerability exists in Meon KYC solutions due to debug mode is enabled in certain API endpoints. A remote attacker could exploit this vulnerability by accessing certain unaut | Apr 23, 2025 | 6.9 | 21 | NO | NO |
CVE-2023-5392HIGH C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recen | Apr 11, 2024 | 7.5 | 21 | NO | NO |
CVE-2025-59109MEDIUM The dormakaba registration units 9002 (PIN Pad Units) have an exposed UART header on the backside. The PIN pad is sending every button press to the UART interface. An attacker can | Jan 26, 2026 | 5.1 | 20 | NO | NO |
CVE-2025-46775MEDIUM A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, F | Nov 18, 2025 | 5.5 | 20 | NO | NO |
CVE-2025-35031MEDIUM Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, | Sep 29, 2025 | 5.5 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.