CWE-201

Insertion of Sensitive Information Into Sent Data

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

294 vulnerabilities with CWE-201
CVE-2024-54309 MEDIUM
wpdebuglog PostBox <1.0.4 - Info Disclosure
CVSS 6.5
CVE-2024-53804 HIGH
WP Mailster <1.8.16.0 - Info Disclosure
CVSS 7.5
CVE-2024-3502 HIGH
lunary-ai/lunary <1.2.5 - Info Disclosure
CVSS 8.1
CVE-2024-50378 MEDIUM
Airflow <2.10.3 - Info Disclosure
CVSS 4.9
CVE-2024-49235 HIGH
VideoWhisper.Com - Info Disclosure
CVSS 7.5
CVE-2024-6747 MEDIUM
Checkmk <2.3.0p18, <2.2.0p36, <2.1.0p49, EOL - Info Disclosure
CVSS 5.3
CVE-2024-47128 MEDIUM
goTenna Pro App - Info Disclosure
CVSS 4.3
CVE-2024-43814 MEDIUM
goTenna Pro ATAK Plugin - Info Disclosure
CVSS 4.3
CVE-2024-41931 MEDIUM
goTenna Pro ATAK Plugin - Info Disclosure
CVSS 4.3
CVE-2024-8890 HIGH
CIRCUTOR Q-SMT <1.0.4 - Info Disclosure
CVSS 8.0
CVE-2024-7698 MEDIUM
Phoenixcontact TC Mguard Rs4000 4G Vzw VPN Firmware < 8.9.3 - CSRF
CVSS 5.7
CVE-2024-6586 HIGH
Lightdash 0.1024.6 - SSRF
CVSS 7.3
CVE-2024-43264 MEDIUM
Mediavine Create <1.9.8 - Info Disclosure
CVSS 5.3
CVE-2024-43259 MEDIUM
JEM Plugins Order Export for WooCommerce - Info Disclosure
CVSS 5.3
CVE-2024-43230 MEDIUM
Shared Files <1.7.28 - Info Disclosure
CVSS 5.3
CVE-2024-43283 MEDIUM
Contest Gallery <23.1.2 - Info Disclosure
CVSS 5.3
CVE-2024-38787 HIGH
Codection <1.26.8 - Info Disclosure
CVSS 7.5
CVE-2024-31200 MEDIUM
Proges Sensor Net Connect Firmware - Information Disclosure via Administrative Session
CVSS 4.2
CVE-2024-7205 CRITICAL
eWeLink Cloud Service <2.19.0 - Privilege Escalation
CVE-2024-38372 LOW
Undici <6.19.2 - Memory Corruption
CVSS 2.0
CVE-2024-39315 MEDIUM
Pomerium < 0.26.1 - XSS
CVSS 5.7
CVE-2024-5213 MEDIUM
mintplex-labs/anything-llm <1.5.3 - Info Disclosure
CVSS 6.5
CVE-2024-37881 MEDIUM
SiteGuard WP Plugin <1.7.7 - Info Disclosure
CVSS 5.3
CVE-2024-35189 MEDIUM
Ethyca Fides < 2.37.0 - Information Disclosure
CVSS 6.5
CVE-2024-34812 MEDIUM
RadiusTheme ShopBuilder - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 294