An attacker with access to the network where the CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could obtain l
Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue af
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
Insertion of Sensitive Information Into Sent Data vulnerability in Simply Static Simply Static simply-static.This issue
Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers i
Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video
Insertion of Sensitive Information Into Sent Data vulnerability in brandtoss WP Mailster wp-mailster allows Retrieve Emb
Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and s
Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and pr
In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse
The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 u
Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `Conne
In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a u
Insertion of Sensitive Information Into Sent Data vulnerability in wpdebuglog PostBox postbox-email-logs allows Retrieve
Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pome
A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount C
In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 be
Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainaca
Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner wit
Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Build
SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measu
Insertion of Sensitive Information Into Sent Data vulnerability in Wasiliy Strecker / ContestGallery developer Contest G
Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue af
Insertion of Sensitive Information Into Sent Data vulnerability in WebFactory Order Export for WooCommerce order-export-
Insertion of Sensitive Information Into Sent Data vulnerability in mischiefmarmot Create by Mediavine mediavine-create.T
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to
Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensiti
Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported v
In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-fo
Insertion of Sensitive Information Into Sent Data vulnerability in DevItems HT Mega ht-mega-for-elementor.This issue aff
Insertion of Sensitive Information Into Sent Data vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite allows Retr
The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broad
The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates
The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast m
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Content Security Man
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows
A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker w
OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `
Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(
When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to take
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents a
An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting
Sentry SDK is the official Python SDK for Sentry, real-time crash reporting software. When using the Django integration
Insertion of Sensitive Information Into Sent Data in GitHub repository answerdev/answer prior to 1.0.8.
An issue has been discovered in GitLab affecting all versions starting from 16.2 before 16.2.8, all versions starting fr
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 prior to 15.11.10, all versions f
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 16.1.5, all versions start
An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side a
Frequently Asked Questions
What is CWE-201?
CWE-201 (CWE-201) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-201?
There are 396 CVE records associated with CWE-201 in our database. Of these, 12 are critical severity, 103 are high severity, and 244 are medium severity.
How can I protect against CWE-201 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-201 using AI-powered security agents.
Detect CWE-201 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-201 vulnerabilities across your infrastructure.
Get Started