CWE-215— Insertion of Sensitive Information Into Debugging Code
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.— MITRE CWE catalog
26 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-215page 1 of 1
- CVE-2024-7569CRITICALCVSS 9.6EG 9.62024-08-13
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
- CVE-2026-40173CRITICALCVSS 9.4EG 9.42026-04-15
Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential disclosure vulnerability where the /debug/pprof/cmdline endpoint is registered on the default mux and reachable without …
- CVE-2026-102628CRITICALCVSS 9.3EG 9.32026-10-01
The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled excep…
- CVE-2026-74799CRITICALCVSS 9.3EG 9.32026-08-17
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set to exactly prod. Attackers can access /debug/pprof/heap and related endpoints to extract …
- CVE-2019-3781HIGHCVSS 8.8EG 8.82019-03-07
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users passwo…
- CVE-2018-1191HIGHCVSS 8.8EG 8.82018-03-29
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
- CVE-2026-22061HIGHCVSS 8.2EG 8.22026-10-09
Trident versions v25.02.1 through v26.06.1 are susceptible to a vulnerability that could allow an authenticated attacker with access to debug logs to view LUKS passphrases or SMB Active Directory credentials.
- CVE-2026-2250HIGHCVSS 7.5EG 7.52026-02-11
The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is conf…
- CVE-2025-34081HIGHCVSS 7.5EG 7.52025-07-01
The Contec Co.,Ltd. CONPROSYS HMI System (CHS) exposes a PHP phpinfo() debug page to unauthenticated users that may contain sensitive data useful for an attacker.This issue affects CONPROSYS HMI System (CHS): before 3.7.7.
- CVE-2025-27684HIGHCVSS 7.5EG 7.52025-03-05
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003.
- CVE-2023-51390HIGHCVSS 7.5EG 7.52023-12-21
journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging…
- CVE-2026-44934HIGHCVSS 7.0EG 7.02026-07-06
A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data o…
- CVE-2025-58598MEDIUMCVSS 6.6EG 6.62025-09-03
Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce klarna-order-management-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Klarna Order Manageme…
- CVE-2022-0721MEDIUMCVSS 6.5EG 6.52022-02-23
Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.
- CVE-2026-20543MEDIUMCVSS 5.5EG 5.52026-10-05
In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645…
- CVE-2026-79694MEDIUMCVSS 5.5EG 5.52026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information Into Debugging Code vulnerability. A low privileged attacker with local access co…
- CVE-2026-62652MEDIUMCVSS 5.3EG 5.32026-09-08
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly…
- CVE-2026-33247MEDIUMCVSS 5.3EG 5.32026-03-25
NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), the…
- CVE-2023-49194MEDIUMCVSS 5.3EG 5.32024-12-09
Insertion of Sensitive Information Into Debugging Code vulnerability in importify Importify (Dropshipping WooCommerce) importify allows Retrieve Embedded Sensitive Data.This issue affects Importify (Dropshipping WooCommerce): from n/a thro…
- CVE-2018-1002104MEDIUMCVSS 5.3EG 5.32020-01-14
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
- CVE-2026-21759MEDIUMCVSS 4.3EG 4.32026-08-24
HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticate…
- CVE-2023-21462MEDIUMCVSS 4.2EG 4.22023-03-16
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
- CVE-2025-12616LOWCVSS 3.7EG 3.72025-11-03
A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possi…
- CVE-2026-33966LOWCVSS 2.8EG 2.82026-09-14
An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.
- CVE-2025-0895LOWCVSS 2.4EG 2.42025-03-02
IBM Cognos Analytics Mobile 1.1 for Android could allow a user with physical access to the device, to obtain sensitive information from debugging code log messages.
- CVE-2024-22194LOWCVSS 2.2EG 2.22024-01-11
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and …
Map vulnerabilities like CWE-215 to your infrastructure
EchelonGraph correlates every CVE — across CWE-215 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →