Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-201

MITRE ↗

CWE-201

3
CRITICAL
58
HIGH
88
MEDIUM
6
LOW
160 CVEs · Page 1/4
9.6
CVE-2026-42880

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0

9.1
CVE-2026-39912

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWi

9.1
CVE-2025-41118

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten

8.6
CVE-2026-67425

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys

8.5
CVE-2026-5483

A flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Ha

8.5
CVE-2026-6267

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and

8.3
CVE-2026-46481

OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION

8.3
CVE-2026-54848

Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R

7.7
CVE-2026-40161

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and

7.7
CVE-2026-42379

Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensi

7.7
CVE-2026-42997

An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut

7.7
CVE-2026-4035

A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew

7.5
CVE-2025-68033

Insertion of Sensitive Information Into Sent Data vulnerability in Brecht Custom Related Posts custom-related-posts allo

7.5
CVE-2025-67931

Insertion of Sensitive Information Into Sent Data vulnerability in AITpro BulletProof Security bulletproof-security allo

7.5
CVE-2025-68035

Insertion of Sensitive Information Into Sent Data vulnerability in tabbyai Tabby Checkout tabby-checkout allows Retrieve

7.5
CVE-2026-24430

Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) disclose sensitive account credentials in

7.5
CVE-2026-24477

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti

7.5
CVE-2020-37093

Netis E1+ 1.2.32533 contains an information disclosure vulnerability that allows unauthenticated attackers to retrieve W

7.5
CVE-2020-37150

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, w

7.5
CVE-2026-27516

Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior expose user passwords in plaintext withi

7.5
CVE-2026-27370

Insertion of Sensitive Information Into Sent Data vulnerability in Premio Chaty chaty allows Retrieve Embedded Sensitive

7.5
CVE-2026-27406

Insertion of Sensitive Information Into Sent Data vulnerability in Joe Dolson My Tickets my-tickets allows Retrieve Embe

7.5
CVE-2026-27934

Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack

7.5
CVE-2026-32829

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, deco

7.5
CVE-2026-33180

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio

7.5
CVE-2026-32538

Insertion of Sensitive Information Into Sent Data vulnerability in Noor Alam SMTP Mailer smtp-mailer allows Retrieve Emb

7.5
CVE-2026-34226

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9

7.5
CVE-2026-4525

If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used t

7.5
CVE-2026-42673

Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity

7.5
CVE-2026-44486

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte

7.5
CVE-2026-44487

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt

7.5
CVE-2026-49064

Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da

7.5
CVE-2026-39480

Unauthenticated Sensitive Data Exposure in Backup Migration <= 2.1.1 versions.

7.5
CVE-2026-40789

Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.

7.5
CVE-2026-42384

Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.

7.5
CVE-2026-42667

Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.

7.5
CVE-2026-52692

Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions.

7.5
CVE-2026-52695

Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.

7.5
CVE-2026-34888

Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.

7.5
CVE-2026-54841

Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.

7.5
CVE-2026-54834

Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.

7.5
CVE-2026-7189

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessin

7.5
CVE-2026-7488

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embed

7.5
CVE-2026-13380

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthent

7.5
CVE-2026-66901

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated

7.5
CVE-2026-65543

Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.

7.5
CVE-2026-47717

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/pro

7.5
CVE-2026-66443

Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.

7.5
CVE-2026-66463

Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.

7.5
CVE-2026-73384

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

Frequently Asked Questions

What is CWE-201?

CWE-201 (CWE-201) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-201?

There are 165 CVE records associated with CWE-201 in our database. Of these, 3 are critical severity, 58 are high severity, and 88 are medium severity.

How can I protect against CWE-201 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-201 using AI-powered security agents.

Detect CWE-201 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-201 vulnerabilities across your infrastructure.

Get Started