Threats Tagged 'cwe-215'
View all threats tagged with 'cwe-215'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-215'
Click on any threat for detailed analysis and mitigation recommendations
0 An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code. Join the discussion | CVE Database V5 | 09/14/2026, 00:00:00 UTC Added: 09/14/2026, 02:47:03 UTC |
0 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information Into Debugging Code vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. Join the discussion | CVE Database V5 | 09/09/2026, 12:29:57 UTC Added: 09/09/2026, 12:38:14 UTC |
0 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities. Join the discussion | GCVE Database | 09/08/2026, 08:11:33 UTC Added: 09/08/2026, 12:55:04 UTC |
0 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more easily reverse engineer the device's firmware, facilitating the identification of further vulnerabilities. Join the discussion | CVE Database V5 | 09/08/2026, 08:11:33 UTC Added: 09/08/2026, 08:37:40 UTC |
0 HCL Hive version 1.0 is affected by an information exposure vulnerability where Swagger API documentation is publicly accessible without authentication. While no sensitive information such as credentials or personally identifiable information was found exposed, the public availability of API documentation can increase the attack surface by revealing implementation details. Join the discussion | CVE Database V5 | 08/24/2026, 12:10:26 UTC Added: 08/24/2026, 12:22:50 UTC |
0 A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials. Join the discussion | CVE Database V5 | 07/06/2026, 08:45:26 UTC Added: 07/06/2026, 08:51:56 UTC |
0 Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without authentication, exposing the full process command line including the admin token configured via the --security "token=..." startup flag. An attacker can retrieve the leaked token and reuse it in the X-Dgraph-AuthToken header to gain unauthorized access to admin-only endpoints such as /admin/config/cache_mb, bypassing the adminAuthHandler token validation. This enables unauthorized privileged administrative access including configuration changes and operational control actions in any deployment where the Alpha HTTP port is reachable by untrusted parties. This issue has been fixed in version 25.3.2. Join the discussion | CVE Database V5 | 04/15/2026, 20:40:47 UTC Added: 04/15/2026, 21:01:56 UTC |
0 NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a configuration file instead of via argv, and do not enable the monitoring port if using secrets in argv. Best practice remains to not expose the monitoring port to the Internet, or to untrusted network sources. Join the discussion | CVE Database V5 | 03/25/2026, 20:02:18 UTC Added: 03/25/2026, 20:15:58 UTC |
0 The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system configuration. Join the discussion | CVE Database V5 | 02/11/2026, 14:13:45 UTC Added: 02/11/2026, 14:31:16 UTC |
0 The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7.7. Join the discussion | CVE Database V5 | 07/01/2025, 17:56:56 UTC Added: 07/01/2025, 18:09:28 UTC |
Showing 1 to 10 of 12 results