Skip to content
Noroxi

CWE-201 · 410 records

Insertion of Sensitive Information Into Sent Data

CVEs in this class

415 records

  • Cisco Jabber Desktop and Mobile Client Software Vulnerabilities

    CriticalCVSS 9.9No exploitEPSS 2%

    cisco · jabberJan 6, 2021

  • Cisco Jabber Desktop and Mobile Client Software Vulnerabilities

    CriticalCVSS 9.9No exploitEPSS 2%

    cisco · jabberDec 11, 2020

  • WordPress Templately Plugin <= 3.2.7 - Sensitive Data Exposure Vulnerability

    CriticalCVSS 10.0No exploitEPSS 0%

    wpdeveloper · templatelyAug 20, 2025

  • Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P

    CriticalCVSS 9.8No exploitEPSS 2%

    elastic · kibanaDec 20, 2018

  • Cisco Jabber Desktop and Mobile Client Software Vulnerabilities

    CriticalCVSS 9.9No exploitEPSS 1%

    cisco · jabberDec 11, 2020

  • Cisco Jabber Desktop and Mobile Client Software Vulnerabilities

    CriticalCVSS 9.9No exploitEPSS 1%

    cisco · jabberDec 11, 2020

  • Cisco Jabber Desktop and Mobile Client Software Vulnerabilities

    CriticalCVSS 9.9No exploitEPSS 1%

    cisco · jabberDec 11, 2020

  • CVE-2026-5483
    39Monitor

    Odh-dashboard: odh dashboard kubernetes service account exposure

    CriticalCVSS 9.9No exploitEPSS 1%

    redhat · openshift aiApr 10, 2026

  • CVE-2024-7205
    37Monitor

    sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user

    CriticalCVSS 9.4No exploitEPSS 0%

    coolkit · ewelink cloud serviceJul 31, 2024

  • Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 all

    CriticalCVSS 9.0No exploitEPSS 2%

    synology · diskstation managerFeb 26, 2021

  • v2board / Xboard Authentication Token Exposure via loginWithMailLink

    CriticalCVSS 9.1Proof of conceptEPSS 1%

    v2board · v2boardApr 9, 2026

  • CVE-2026-8924
    36Monitor

    trailing dot domain super cookie

    CriticalCVSS 9.1No exploitEPSS 1%

    haxx · curlJul 3, 2026

  • Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Da

    CriticalCVSS 9.1No exploitEPSS 0%

    netwrix · directory managerMay 28, 2025

  • VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses

    CriticalCVSS 9.0No exploitEPSS 0%

    vsee · clinicJul 20, 2026

  • AnythingLLM has key leak in `systemSettings.js`

    HighCVSS 8.7Proof of conceptEPSS 2%

    mintplexlabs · anythingllmJan 26, 2026

  • GOAUTH credential leak in cmd/go

    HighCVSS 8.8No exploitEPSS 1%

    go toolchain · cmd/goJan 27, 2025

  • XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgery

    HighCVSS 8.8No exploitEPSS 1%

    xwiki · xwikiNov 20, 2023

  • CVE-2026-4525
    35Monitor

    Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header

    HighCVSS 8.8No exploitEPSS 1%

    hashicorp · vaultApr 17, 2026

  • Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeover

    HighCVSS 8.8No exploitEPSS 1%

    gtbabel · gtbabelMar 10, 2025

  • CVE-2024-8890
    35Monitor

    Insertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMT

    HighCVSS 8.8No exploitEPSS 0%

    circutor · q-smt firmwareSep 18, 2024

  • Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure

    HighCVSS 8.7No exploitEPSS 1%

    edimax · ew-7438rpn mini firmwareFeb 5, 2026

  • MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosure

    HighCVSS 8.7No exploitEPSS 1%

    mici network co. ltd. · netfax serverMay 29, 2025

  • Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

    HighCVSS 8.6No exploitEPSS 1%

    flytohub · flyto-coreJul 29, 2026

  • Bullfrog's DNS over TCP bypasses domain filtering

    HighCVSS 8.6No exploitEPSS 0%

    bullfrogsec · bullfrogMay 14, 2025

  • XWiki makes title of inaccessible pages available through the class property values REST API

    HighCVSS 8.7No exploitEPSS 0%

    xwiki · xwikiJun 13, 2025

All vulnerability classes