The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
Volume of CVEs assigned to CWE-215 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44934HIGH A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, | Jul 6, 2026 | 7.0 | 33 | NO | NO |
CVE-2026-40173CRITICAL Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpo | Apr 15, 2026 | 9.4 | 32 | NO | NO |
CVE-2024-7569CRITICAL An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret | Aug 13, 2024 | 9.8 | 31 | NO | NO |
CVE-2019-3781HIGH Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user | Mar 7, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-1191HIGH Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and | Mar 29, 2018 | 8.8 | 27 | NO | NO |
CVE-2026-2250HIGH The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensit | Feb 11, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33247MEDIUM NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credential | Mar 25, 2026 | 5.3 | 22 | NO | NO |
CVE-2025-58598MEDIUM Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce klarna-order-management-for-woocommerce allows Retrieve Embed | Sep 3, 2025 | 6.6 | 22 | NO | NO |
CVE-2025-27684HIGH Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003. | Mar 5, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-12616MEDIUM A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertio | Nov 3, 2025 | 5.9 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.