CWE-201 · 410 records
Insertion of Sensitive Information Into Sent Data
CVEs in this class
415 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-26085No exploit | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Critical9.9 | — | 2.2% | Jan 6, 2021 |
40Plan | CVE-2020-27134No exploit | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Critical9.9 | — | 1.7% | Dec 11, 2020 |
40Plan | CVE-2025-49408No exploit | WordPress Templately Plugin <= 3.2.7 - Sensitive Data Exposure Vulnerabilitywpdeveloper · templately · CWE-201 | Critical10.0 | — | 0.5% | Aug 20, 2025 |
39Monitor | CVE-2018-17245No exploit | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating Pelastic · kibana · CWE-201 | Critical9.8 | — | 1.5% | Dec 20, 2018 |
39Monitor | CVE-2020-27132No exploit | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Critical9.9 | — | 1.4% | Dec 11, 2020 |
39Monitor | CVE-2020-27127No exploit | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Critical9.9 | — | 1.4% | Dec 11, 2020 |
39Monitor | CVE-2020-27133No exploit | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Critical9.9 | — | 1.1% | Dec 11, 2020 |
39Monitor | CVE-2026-5483No exploit | Odh-dashboard: odh dashboard kubernetes service account exposureredhat · openshift ai · CWE-201 | Critical9.9 | — | 0.7% | Apr 10, 2026 |
37Monitor | CVE-2024-7205No exploit | sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary usercoolkit · ewelink cloud service · CWE-201 | Critical9.4 | — | 0.5% | Jul 31, 2024 |
36Monitor | CVE-2021-26566No exploit | Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allsynology · diskstation manager · CWE-201 | Critical9.0 | — | 1.5% | Feb 26, 2021 |
36Monitor | CVE-2026-39912Proof of concept | v2board / Xboard Authentication Token Exposure via loginWithMailLinkv2board · v2board · CWE-201 | Critical9.1 | — | 0.7% | Apr 9, 2026 |
36Monitor | CVE-2026-8924No exploit | trailing dot domain super cookiehaxx · curl · CWE-201 | Critical9.1 | — | 0.7% | Jul 3, 2026 |
36Monitor | CVE-2025-48749No exploit | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Danetwrix · directory manager · CWE-201 | Critical9.1 | — | 0.4% | May 28, 2025 |
36Monitor | CVE-2026-13380No exploit | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responsesvsee · clinic · CWE-201 | Critical9.0 | — | 0.4% | Jul 20, 2026 |
35Monitor | CVE-2026-24477Proof of concept | AnythingLLM has key leak in `systemSettings.js`mintplexlabs · anythingllm · CWE-201 | High8.7 | — | 1.7% | Jan 26, 2026 |
35Monitor | CVE-2024-45340No exploit | GOAUTH credential leak in cmd/gogo toolchain · cmd/go · CWE-201 | High8.8 | — | 0.7% | Jan 27, 2025 |
35Monitor | CVE-2023-48240No exploit | XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryxwiki · xwiki · CWE-201 | High8.8 | — | 0.7% | Nov 20, 2023 |
35Monitor | CVE-2026-4525No exploit | Vault Token Leaked to Backends via Authorization: Bearer Passthrough Headerhashicorp · vault · CWE-201 | High8.8 | — | 0.6% | Apr 17, 2026 |
35Monitor | CVE-2024-11638No exploit | Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeovergtbabel · gtbabel · CWE-201 | High8.8 | — | 0.5% | Mar 10, 2025 |
35Monitor | CVE-2024-8890No exploit | Insertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMTcircutor · q-smt firmware · CWE-201 | High8.8 | — | 0.4% | Sep 18, 2024 |
34Monitor | CVE-2020-37150No exploit | Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosureedimax · ew-7438rpn mini firmware · CWE-201 | High8.7 | — | 0.8% | Feb 5, 2026 |
34Monitor | CVE-2025-48045No exploit | MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosuremici network co. ltd. · netfax server · CWE-201 | High8.7 | — | 0.6% | May 29, 2025 |
34Monitor | CVE-2026-67425No exploit | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlflytohub · flyto-core · CWE-201 | High8.6 | — | 0.6% | Jul 29, 2026 |
34Monitor | CVE-2025-47775No exploit | Bullfrog's DNS over TCP bypasses domain filteringbullfrogsec · bullfrog · CWE-201 | High8.6 | — | 0.5% | May 14, 2025 |
34Monitor | CVE-2025-49584No exploit | XWiki makes title of inaccessible pages available through the class property values REST APIxwiki · xwiki · CWE-201 | High8.7 | — | 0.4% | Jun 13, 2025 |
- CVE-2020-2608540Plan
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
CriticalCVSS 9.9No exploitEPSS 2%cisco · jabberJan 6, 2021
- CVE-2020-2713440Plan
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
CriticalCVSS 9.9No exploitEPSS 2%cisco · jabberDec 11, 2020
- CVE-2025-4940840Plan
WordPress Templately Plugin <= 3.2.7 - Sensitive Data Exposure Vulnerability
CriticalCVSS 10.0No exploitEPSS 0%wpdeveloper · templatelyAug 20, 2025
- CVE-2018-1724539Monitor
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P
CriticalCVSS 9.8No exploitEPSS 2%elastic · kibanaDec 20, 2018
- CVE-2020-2713239Monitor
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
CriticalCVSS 9.9No exploitEPSS 1%cisco · jabberDec 11, 2020
- CVE-2020-2712739Monitor
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
CriticalCVSS 9.9No exploitEPSS 1%cisco · jabberDec 11, 2020
- CVE-2020-2713339Monitor
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
CriticalCVSS 9.9No exploitEPSS 1%cisco · jabberDec 11, 2020
- CVE-2026-548339Monitor
Odh-dashboard: odh dashboard kubernetes service account exposure
CriticalCVSS 9.9No exploitEPSS 1%redhat · openshift aiApr 10, 2026
- CVE-2024-720537Monitor
sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
CriticalCVSS 9.4No exploitEPSS 0%coolkit · ewelink cloud serviceJul 31, 2024
- CVE-2021-2656636Monitor
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 all
CriticalCVSS 9.0No exploitEPSS 2%synology · diskstation managerFeb 26, 2021
- CVE-2026-3991236Monitor
v2board / Xboard Authentication Token Exposure via loginWithMailLink
CriticalCVSS 9.1Proof of conceptEPSS 1%v2board · v2boardApr 9, 2026
- CVE-2026-892436Monitor
trailing dot domain super cookie
CriticalCVSS 9.1No exploitEPSS 1%haxx · curlJul 3, 2026
- CVE-2025-4874936Monitor
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Da
CriticalCVSS 9.1No exploitEPSS 0%netwrix · directory managerMay 28, 2025
- CVE-2026-1338036Monitor
VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
CriticalCVSS 9.0No exploitEPSS 0%vsee · clinicJul 20, 2026
- CVE-2026-2447735Monitor
AnythingLLM has key leak in `systemSettings.js`
HighCVSS 8.7Proof of conceptEPSS 2%mintplexlabs · anythingllmJan 26, 2026
- CVE-2024-4534035Monitor
GOAUTH credential leak in cmd/go
HighCVSS 8.8No exploitEPSS 1%go toolchain · cmd/goJan 27, 2025
- CVE-2023-4824035Monitor
XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgery
HighCVSS 8.8No exploitEPSS 1%xwiki · xwikiNov 20, 2023
- CVE-2026-452535Monitor
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
HighCVSS 8.8No exploitEPSS 1%hashicorp · vaultApr 17, 2026
- CVE-2024-1163835Monitor
Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeover
HighCVSS 8.8No exploitEPSS 1%gtbabel · gtbabelMar 10, 2025
- CVE-2024-889035Monitor
Insertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMT
HighCVSS 8.8No exploitEPSS 0%circutor · q-smt firmwareSep 18, 2024
- CVE-2020-3715034Monitor
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure
HighCVSS 8.7No exploitEPSS 1%edimax · ew-7438rpn mini firmwareFeb 5, 2026
- CVE-2025-4804534Monitor
MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosure
HighCVSS 8.7No exploitEPSS 1%mici network co. ltd. · netfax serverMay 29, 2025
- CVE-2026-6742534Monitor
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
HighCVSS 8.6No exploitEPSS 1%flytohub · flyto-coreJul 29, 2026
- CVE-2025-4777534Monitor
Bullfrog's DNS over TCP bypasses domain filtering
HighCVSS 8.6No exploitEPSS 0%bullfrogsec · bullfrogMay 14, 2025
- CVE-2025-4958434Monitor
XWiki makes title of inaccessible pages available through the class property values REST API
HighCVSS 8.7No exploitEPSS 0%xwiki · xwikiJun 13, 2025