CWE-215: Insertion of Sensitive Information Into Debugging Code
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
21 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-40173 — Dgraph: Unauthenticated pprof endpoint leaks admin auth token
- CVE-2026-74799 — SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure
- CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC
- CVE-2025-34081 — CONPROSYS HMI System (CHS) < 3.7.7 Exposed PHP Debug Info
- CVE-2026-33247 — NATS credentials are exposed in monitoring port via command-line argv
- CVE-2026-44934 — Exposed tokens in SUSE Rancher AI Agent logs
- CVE-2026-62652 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from
- CVE-2025-58598 — WordPress Klarna Order Management for WooCommerce Plugin <= 1.9.8 - Sensitive Data Exposure Vulnerability
- CVE-2026-79694 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-21759 — HCL Hive is affected by an information exposure vulnerability
- CVE-2025-0895 — IBM Cognos Mobile information disclosure
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
Recently published
- CVE-2026-79694 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-62652 — A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from
- CVE-2026-21759 — HCL Hive is affected by an information exposure vulnerability
- CVE-2026-74799 — SiYuan before 3.7.4 Unauthenticated Debug Endpoint Information Disclosure
- CVE-2026-44934 — Exposed tokens in SUSE Rancher AI Agent logs
- CVE-2026-40173 — Dgraph: Unauthenticated pprof endpoint leaks admin auth token
- CVE-2026-33247 — NATS credentials are exposed in monitoring port via command-line argv
- CVE-2026-2250 — Unauthenticated Data Export and Source Code Disclosure via /dbviewer/ in METIS WIC
- CVE-2025-58598 — WordPress Klarna Order Management for WooCommerce Plugin <= 1.9.8 - Sensitive Data Exposure Vulnerability
- CVE-2025-34081 — CONPROSYS HMI System (CHS) < 3.7.7 Exposed PHP Debug Info
- CVE-2025-0895 — IBM Cognos Mobile information disclosure
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code