CWE-201 · 409 записей
Insertion of Sensitive Information Into Sent Data
CVE этого класса
410 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-26085Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Критическая9,9 | — | 2,2 % | 6 янв. 2021 г. |
40В плане | CVE-2020-27134Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Критическая9,9 | — | 1,7 % | 11 дек. 2020 г. |
40В плане | CVE-2025-49408Эксплойта нет | WordPress Templately Plugin <= 3.2.7 - Sensitive Data Exposure Vulnerabilitywpdeveloper · templately · CWE-201 | Критическая10,0 | — | 0,5 % | 20 авг. 2025 г. |
39Наблюдать | CVE-2018-17245Эксплойта нет | Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating Pelastic · kibana · CWE-201 | Критическая9,8 | — | 1,5 % | 20 дек. 2018 г. |
39Наблюдать | CVE-2020-27132Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Критическая9,9 | — | 1,4 % | 11 дек. 2020 г. |
39Наблюдать | CVE-2020-27127Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Критическая9,9 | — | 1,4 % | 11 дек. 2020 г. |
39Наблюдать | CVE-2020-27133Эксплойта нет | Cisco Jabber Desktop and Mobile Client Software Vulnerabilitiescisco · jabber · CWE-201 | Критическая9,9 | — | 1,1 % | 11 дек. 2020 г. |
39Наблюдать | CVE-2026-5483Эксплойта нет | Odh-dashboard: odh dashboard kubernetes service account exposureredhat · openshift ai · CWE-201 | Критическая9,9 | — | 0,7 % | 10 апр. 2026 г. |
37Наблюдать | CVE-2024-7205Эксплойта нет | sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary usercoolkit · ewelink cloud service · CWE-201 | Критическая9,4 | — | 0,5 % | 31 июл. 2024 г. |
36Наблюдать | CVE-2021-26566Эксплойта нет | Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allsynology · diskstation manager · CWE-201 | Критическая9,0 | — | 1,5 % | 26 февр. 2021 г. |
36Наблюдать | CVE-2026-39912Proof of concept | v2board / Xboard Authentication Token Exposure via loginWithMailLinkv2board · v2board · CWE-201 | Критическая9,1 | — | 0,7 % | 9 апр. 2026 г. |
36Наблюдать | CVE-2026-8924Эксплойта нет | trailing dot domain super cookiehaxx · curl · CWE-201 | Критическая9,1 | — | 0,7 % | 3 июл. 2026 г. |
36Наблюдать | CVE-2025-48749Эксплойта нет | Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Danetwrix · directory manager · CWE-201 | Критическая9,1 | — | 0,4 % | 28 мая 2025 г. |
36Наблюдать | CVE-2026-13380Эксплойта нет | VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responsesvsee · clinic · CWE-201 | Критическая9,0 | — | 0,4 % | 20 июл. 2026 г. |
35Наблюдать | CVE-2026-24477Proof of concept | AnythingLLM has key leak in `systemSettings.js`mintplexlabs · anythingllm · CWE-201 | Высокая8,7 | — | 1,7 % | 26 янв. 2026 г. |
35Наблюдать | CVE-2024-45340Эксплойта нет | GOAUTH credential leak in cmd/gogo toolchain · cmd/go · CWE-201 | Высокая8,8 | — | 0,7 % | 27 янв. 2025 г. |
35Наблюдать | CVE-2023-48240Эксплойта нет | XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryxwiki · xwiki · CWE-201 | Высокая8,8 | — | 0,7 % | 20 нояб. 2023 г. |
35Наблюдать | CVE-2026-4525Эксплойта нет | Vault Token Leaked to Backends via Authorization: Bearer Passthrough Headerhashicorp · vault · CWE-201 | Высокая8,8 | — | 0,6 % | 17 апр. 2026 г. |
35Наблюдать | CVE-2024-11638Эксплойта нет | Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeovergtbabel · gtbabel · CWE-201 | Высокая8,8 | — | 0,5 % | 10 мар. 2025 г. |
35Наблюдать | CVE-2024-8890Эксплойта нет | Insertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMTcircutor · q-smt firmware · CWE-201 | Высокая8,8 | — | 0,4 % | 18 сент. 2024 г. |
34Наблюдать | CVE-2020-37150Эксплойта нет | Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosureedimax · ew-7438rpn mini firmware · CWE-201 | Высокая8,7 | — | 0,8 % | 5 февр. 2026 г. |
34Наблюдать | CVE-2025-48045Эксплойта нет | MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosuremici network co. ltd. · netfax server · CWE-201 | Высокая8,7 | — | 0,6 % | 29 мая 2025 г. |
34Наблюдать | CVE-2026-67425Эксплойта нет | Flyto2 Core: LLM/API keys leak to an attacker-controlled base_urlflytohub · flyto-core · CWE-201 | Высокая8,6 | — | 0,6 % | 29 июл. 2026 г. |
34Наблюдать | CVE-2025-47775Эксплойта нет | Bullfrog's DNS over TCP bypasses domain filteringbullfrogsec · bullfrog · CWE-201 | Высокая8,6 | — | 0,5 % | 14 мая 2025 г. |
34Наблюдать | CVE-2025-49584Эксплойта нет | XWiki makes title of inaccessible pages available through the class property values REST APIxwiki · xwiki · CWE-201 | Высокая8,7 | — | 0,4 % | 13 июн. 2025 г. |
- CVE-2020-2608540В плане
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %cisco · jabber6 янв. 2021 г.
- CVE-2020-2713440В плане
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %cisco · jabber11 дек. 2020 г.
- CVE-2025-4940840В плане
WordPress Templately Plugin <= 3.2.7 - Sensitive Data Exposure Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %wpdeveloper · templately20 авг. 2025 г.
- CVE-2018-1724539Наблюдать
Kibana versions 4.0 to 4.6, 5.0 to 5.6.12, and 6.0 to 6.4.2 contain an error in the way authorization credentials are used when generating P
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %elastic · kibana20 дек. 2018 г.
- CVE-2020-2713239Наблюдать
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cisco · jabber11 дек. 2020 г.
- CVE-2020-2712739Наблюдать
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cisco · jabber11 дек. 2020 г.
- CVE-2020-2713339Наблюдать
Cisco Jabber Desktop and Mobile Client Software Vulnerabilities
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %cisco · jabber11 дек. 2020 г.
- CVE-2026-548339Наблюдать
Odh-dashboard: odh dashboard kubernetes service account exposure
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %redhat · openshift ai10 апр. 2026 г.
- CVE-2024-720537Наблюдать
sharing unnecessary device-sensitive information allows Secondary user able to take over devices as primary user
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %coolkit · ewelink cloud service31 июл. 2024 г.
- CVE-2021-2656636Наблюдать
Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 all
КритическаяCVSS 9,0Эксплойта нетEPSS 2 %synology · diskstation manager26 февр. 2021 г.
- CVE-2026-3991236Наблюдать
v2board / Xboard Authentication Token Exposure via loginWithMailLink
КритическаяCVSS 9,1Proof of conceptEPSS 1 %v2board · v2board9 апр. 2026 г.
- CVE-2026-892436Наблюдать
trailing dot domain super cookie
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %haxx · curl3 июл. 2026 г.
- CVE-2025-4874936Наблюдать
Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Information into Sent Da
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %netwrix · directory manager28 мая 2025 г.
- CVE-2026-1338036Наблюдать
VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %vsee · clinic20 июл. 2026 г.
- CVE-2026-2447735Наблюдать
AnythingLLM has key leak in `systemSettings.js`
ВысокаяCVSS 8,7Proof of conceptEPSS 2 %mintplexlabs · anythingllm26 янв. 2026 г.
- CVE-2024-4534035Наблюдать
GOAUTH credential leak in cmd/go
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %go toolchain · cmd/go27 янв. 2025 г.
- CVE-2023-4824035Наблюдать
XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgery
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %xwiki · xwiki20 нояб. 2023 г.
- CVE-2026-452535Наблюдать
Vault Token Leaked to Backends via Authorization: Bearer Passthrough Header
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hashicorp · vault17 апр. 2026 г.
- CVE-2024-1163835Наблюдать
Gtbabel < 6.6.9 - Unauthenticated Admin Account Takeover
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %gtbabel · gtbabel10 мар. 2025 г.
- CVE-2024-889035Наблюдать
Insertion of Sensitive Information Into Sent Data vulnerability on CIRCUTOR Q-SMT
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %circutor · q-smt firmware18 сент. 2024 г.
- CVE-2020-3715034Наблюдать
Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %edimax · ew-7438rpn mini firmware5 февр. 2026 г.
- CVE-2025-4804534Наблюдать
MICI Network Co. Ltd. NetFax Server Default Administrator Credentials Disclosure
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mici network co. ltd. · netfax server29 мая 2025 г.
- CVE-2026-6742534Наблюдать
Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %flytohub · flyto-core29 июл. 2026 г.
- CVE-2025-4777534Наблюдать
Bullfrog's DNS over TCP bypasses domain filtering
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %bullfrogsec · bullfrog14 мая 2025 г.
- CVE-2025-4958434Наблюдать
XWiki makes title of inaccessible pages available through the class property values REST API
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %xwiki · xwiki13 июн. 2025 г.