CWE-201
Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
367 vulnerabilities with CWE-201
CVE-2026-24427
MEDIUM
Shenzhen Tenda AC7 <V03.03.03.01_cn - Info Disclosure
CVSS 5.5
CVE-2026-24992
MEDIUM
WPFactory Advanced WooCommerce Product Sales Reporting <4.1.2 - Inf...
CVSS 5.3
CVE-2026-1539
MEDIUM
libsoup - Proxy-Authorization Header Credential Disclosure
CVSS 5.8
CVE-2026-24477
HIGH
AnythingLLM <1.10.0 - Info Disclosure
CVSS 7.5
CVE-2026-24430
HIGH
Shenzhen Tenda W30E V2 <16.01.0.19(5037) - Info Disclosure
CVSS 7.5
CVE-2026-24589
MEDIUM
Cargus eCommerce Cargus <= 1.5.8 - Sensitive Data Exposure via Embedded Data Retrieval
CVSS 5.3
CVE-2026-24565
MEDIUM
bPlugins B Accordion <2.0.0 - Info Disclosure
CVSS 6.5
CVE-2026-24559
MEDIUM
CRM Perks Integration for Contact Form 7 HubSpot <1.4.3 - Info Disc...
CVSS 5.3
CVE-2026-24557
MEDIUM
WEN Solutions Contact Form 7 GetResponse Extension <1.0.9 - Info Di...
CVSS 5.3
CVE-2026-23878
MEDIUM
HotCRP - Unauthenticated Sensitive Information Disclosure via Document API
CVSS 6.5
CVE-2026-22246
MEDIUM
Mastodon < 4.3.17 - Unauthenticated Information Disclosure via Severed Relationship Notifications
CVSS 6.5
CVE-2026-22539
MEDIUM
EFACEC QC 60/90/120 - Unauthenticated Information Disclosure via OCPP v1.6
CVE-2025-69132
MEDIUM
WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability
CVSS 6.5
CVE-2025-62309
LOW
HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields.
CVSS 2.6
CVE-2025-62308
MEDIUM
HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed
CVSS 5.1
CVE-2025-62305
MEDIUM
HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions
CVSS 5.1
CVE-2025-31978
MEDIUM
HCL BigFix Service Management (SM) does not adequately sanitize or safely render
CVSS 4.6
CVE-2025-41118
CRITICAL
Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection
CVSS 9.1
CVE-2025-11500
HIGH
Credentials exposure in tinycontrol devices
CVE-2025-14483
MEDIUM
IBM Sterling B2B Integrator 6.1.0.0-6.1.2.7_2 - Info Disclosure
CVSS 4.3
CVE-2025-68515
MEDIUM
WP Booking System <=2.0.19.12 - Info Disclosure
CVSS 5.8
CVE-2025-68855
MEDIUM
JobBoard Job listing <=1.2.8 - Info Disclosure
CVSS 5.9
CVE-2025-7708
MEDIUM
Atlas Educational Software Industry Ltd. Co. K12net <09022026 - Inf...
CVSS 6.8
CVE-2025-15329
MEDIUM
Tanium Threat Response 4.5.0-4.5.250 - Information Disclosure
CVSS 4.9
CVE-2025-67857
MEDIUM
moodle < 4.1.21 and >= 0 < 4.1.22 - Unauthenticated User Identifier Exposure in Anonymous Assignment Submission URLs
CVSS 4.3
Details
Vulnerabilities
367